braindump2go.70-411 - gratis exam...mix-qa question 1 your network contains a single active...

169
Braindump2go.70-411 Number : 70-411 Passing Score : 700 Time Limit : 120 min File Version : 1.0 http://www.gratisexam.com/ Vendor: Microsoft Exam Code: 70-411 Exam Name: Administering Windows Server 2012 Passed the exam 1000/1000, great dump. Sections 1. Non Mobile VCE's

Upload: others

Post on 28-May-2020

2 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Braindump2go.70-411

Number: 70-411Passing Score: 700Time Limit: 120 minFile Version: 1.0

http://www.gratisexam.com/

Vendor: Microsoft

Exam Code: 70-411

Exam Name: Administering Windows Server 2012

Passed the exam 1000/1000, great dump.

Sections1. Non Mobile VCE's

Page 2: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Mix-QA

QUESTION 1Your network contains a single Active Directory domain named contoso.com. The domain contains a memberserver named Server1 that runs Windows Server 2012. Server1 has the Windows Server Updates Services server role installed and is configured to download updatesfrom the Microsoft Update servers.You need to ensure that Server1 downloads express installation files from the Microsoft Update servers.

What should you do from the Update Services console?

A. From the Automatic Approvals options, configure the Update Rules settings.B. From the Products and Classifications options, configure the Classifications settings.C. From the Products and Classifications options, configure the Products settings.D. From the Update Files and Languages options, configure the Update Files settings.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc708431.aspx

To specify whether express installation files are d ownloaded during synchronizationIn the left pane of the WSUS Administration console, click Options .In Update Files and Languages , click the Update Files tab.If you want to download express installation files, select the Download express installation files check box. Ifyou do not want to download express installation files, clear the check box.

QUESTION 2You have a VHD that contains an image of Windows Server 2012. You plan to apply updates to the image.You need to ensure that only updates that can install without requiring a restart are installed.

Which DISM option should you use?

A. /PreventPendingB. /Apply-UnattendC. /Cleanup-ImageD. /Add-ProvisionedAppxPackage

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/hh852164.aspx

- PreventPendingSkips the installation of the package if the package or Windows image has pending online actions.

QUESTION 3Your network contains an Active Directory domain named adatum.com. The domain contains a server namedWDS1 that runs Windows Server 2012. You install the Windows Deployment Services server role on WDS1. You have a virtual machine named VM1that runs Windows Server 2012. VM1 has several line-of-business applications installed.You need to create an image of VM1 by using Windows Deployment Services.

Page 3: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which type of image should you add to VM1 first?

A. CaptureB. InstallC. DiscoveryD. Boot

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://itadmintips.wordpress.com/2011/05/19/wds-setup-guide-part-2-boot-image-setup/

QUESTION 4Which of the options should you configure for a WDS pre-staged computer name? You should select 2 of the 4check boxes.

A. GUID o MAC-address preceding with nullsB. WdsClientUnattend

C. give the minimum required permission to a user who wants to promote a RODC.

D. ReferralServer

Correct Answer: ACSection: (none)Explanation

Explanation/Reference:WDSUTIL /Add-Device /Device:Computer1 /ID: GUID o MAC

adicionales:/ReferralServer:WDSServer1 /BootProgram:boot\x86\pxeboot.com/WDSClientUnattend:WDSClientUnattend\unattend.xml/User:Domain\MyUser /JoinRights:Full /BootImagePath:boot\x86\images\boot.wim /OU:"OU=MyOU,CN=Test,DC=Domain,DC=com"

Las Opciones son:[/ReferralServer:<Server name>] [/BootProgram:<Relative path>] [/WdsClientUnattend:<Relative path>] [/User:<Domain\User | User@Domain>] [/JoinRights:{JoinOnly | Full}] [/JoinDomain:{Yes | No}] [/BootImagePath:<Relative path>] [/OU:<DN of OU>] [/Domain:<Domain>]

http://technet.microsoft.com/en-us/library/cc754469.aspx

Click Start, right-click Command Prompt, and then click Run as administrator.

Type the following, where <devicename> is the name and <GUIDorMACAddress> is the identifier of the newcomputer. If you use a MAC address with the /ID option, you must precede it with twenty zeros (0).

WDSUTIL /add-device /device:<devicename> /ID:<GUIDorMACAddress> <options>

Page 4: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

For example: WDSUTIL /Add-Device /Device:Computer1 /ID:{E8A3EFAC-201F-4E69-953F-B2DAA1E8B1B6} /ReferralServer: WDSServer1 /BootProgram:boot\x86\pxeboot.com /WDSClientUnattend :WDSClientUnattend\unattend.xml /User: Domain\MyUser/JoinRights:Full /BootImagePath :boot\x86\images\boot.wim /OU:"OU=MyOU,CN=Test,DC=Domain,DC=com"

Mediante WDSUTIL. Usted puede ensayar previamente equipos cliente antes de haber intentado un arranquede red mediante la línea de comandos. Tenga en cuenta que no se puede ensayar previamente equiposmediante la MMC de Servicios de implementación de Windows Server, pero se puede establecer laConfiguración de la directiva de adición automática y aprobar o rechazar los equipos pendientes.

La directiva de adición automática especifica que se requiere la autorización administrativa antes de losordenadores desconocidos (equipos que no se han ensayado previamente en los Servicios de dominio deActive Directory (AD DS)) se permite la instalación de un sistema operativo. Cuando se habilita esta directiva,los clientes que están en espera de aprobación se mostrarán en el nodo Dispositivos pendientes delcomplemento MMC. Si apruebas el equipo en espera, el equipo seguirá el arranque desde la red, y un objetode cuenta de equipo se creará en AD DS para representar el equipo físico. Esto es útil porque te da laposibilidad de preconfigurar los ordenadores sin necesidad de conocer el GUID del equipo cliente o ladirección MAC de antemano. Si rechaza el ordenador, el arranque de red se detendrá, el equipo se iniciarádesde el siguiente punto en el orden de arranque, y una cuenta de equipo no se creará.

Si no habilita la directiva de adición automática, Servicios de implementación de Windows no va a crear unacuenta de equipo para clientes desconocidos cuando el primer arranque PXE. Sin embargo, una cuentatodavía será creado como parte de la instalación si el servidor está configurado para unirse a los clientes aldominio. Para configurar esta opción, haga clic en el servidor, y haga clic en Propiedades. En la ficha delcliente, consulte la sección Unirse a un dominio.

Nota:Before you can prestage computers, you need to update your Active Directory Users and Computers console.The following update will enable the screen which allows you to input the GUID when creating new computeraccounts.

You need the following files from your server and they have to be the same architecture, so if yourworkstation is x64, then so does the server. %systemroot%\system32\imadmui.dll %systemroot%\system32\en-US\imadmui.dll.mui Copy those files to the same location on your workstation. Register the dll using the following command as an administrator (remember UAC):regsvr32 imadmui.dll

QUESTION 5Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2008 R2.

You plan to test Windows Server 2012 by using native-boot virtual hard disks (VHDs).

You attach a new VHD to Server1.

You need to install Windows Server 2102 in the VHD.

What should you do?

A. Run dism.exe and specify the /apply-image parameter.B. Run dism.exe and specify the /append-image parameter.C. Run imagex.exe and specify the /export parameter.D. Run imagex.exe and specify the /append parameter.

Correct Answer: A

Page 5: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 6You have a server named Admin1 that runs Windows Server 2012.

On Admin1, you configure a custom Data Collector Set (DCS) named DCS1. DCS1 is configured to storeperformance log data in C:\Logs.

You need to ensure that the contents of C:\Logs are deleted automatically when the folder reaches 100 MB insize.

What should you configure?

A. A File Server Resource Manager (FSRM) quota on the C:\Logs folderB. A File Server Resource Manager (FSRM) file screen on the C:\Logs folderC. A schedule for DCS1D. The Data Manager settings of DCS1

Correct Answer: DSection: (none)Explanation

Explanation/Reference:Reference:

http://sourcedaddy.com/windows-7/using-data-manager-view-performance-data.html

QUESTION 7Your network contains an Active Directory domain named contoso.com. The domain does not contain acertification authority (CA).All servers run Windows Server 2012. All client computers run Windows 8.You need to add a data recovery agent for the Encrypting File System (EFS) to the domain.

http://www.gratisexam.com/

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A. From Windows PowerShell, run Get-Certificate.B. From the Default Domain Controllers Policy, select Create Data Recovery Agent.C. From the Default Domain Policy, select Add Data Recovery Agent.D. From a command prompt, run cipher.exe.E. From the Default Domain Policy, select Create Data Recovery Agent.F. From the Default Domain Controllers Policy, select Add Data Recovery Agent.

Correct Answer: ACSection: (none)

Page 6: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:

QUESTION 8Your network contains an Active Directory domain named contoso.com. The domain contains three domaincontrollers. The domain controllers are configured as shown in the following table.

You are creating a Distributed File System (DFS) namespace as shown in the exhibit. (Click the Exhibit button.)You need to identify which configuration prevents you from creating a DFS namespace in Windows Server2008 mode.

Which configuration should you identify?

Exhibit:

Page 7: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. The location of the PDC emulator roleB. The functional level of the domainC. The operating system on Server1 and Server3D. The location of the RID master role

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/ff633469(v=WS.10).aspxMigrate the following domain-based namespace from Windows 2000 Server mode to Windows Server 2008mode.

QUESTION 9Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table.

Page 8: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption(BitLocker) on all local disk drives.You need to deploy the Network Unlock feature.The solution must minimize the number of features and server roles installed on the network.

To which server should you deploy the feature?

A. Server3B. Server1C. DC2D. Server2E. DC1

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/jj574173.aspxThe BitLocker-NetworkUnlock feature must be installed on a Windows Deployment Server (which does nothave to be configured--the WDSServer service just needs to be running).

QUESTION 10Your network contains multiple Active Directory sites. You have a Distributed File System (DFS) namespacethat has a folder target in each site. You discover that some client computers connect to DFS targets in other sites.You need to ensure that the client computers only connect to a DFS target in their respective site.

What should you modify?

A. The properties of the Active Directory sitesB. The properties of the Active Directory site linksC. The delegation settings of the namespaceD. The referral settings of the namespace

Correct Answer: DSection: (none)Explanation

Page 9: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:http://www.windowsnetworking.com/articles_tutorials/Configuring-DFS-Namespaces.html

QUESTION 11You have a server named Server1 that runs Windows Server 2012. Server1 has the File Server ResourceManager role service installed. Server1 has a folder named Folder1 that is used by the sales department.You need to ensure that an email notification is sent to the sales manager when a File Screening Audit report isgenerated.

What should you configure on Server1?

A. A file screen exceptionB. A file groupC. A storage report taskD. A file screen

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc755988.aspx

Before you run a File Screen Audit report, in the File Server Resource Manager Options dialog box, on the FileScreen Audit tab, verify that the Record file screening activity in the auditing database check box is selected.

QUESTION 12Your network contains an Active Directory domain named contoso.com. The domain contains two serversnamed Server1 and Server2. Both servers run Windows Server 2012. Both servers have the File and Storage Services server role. The DFS Namespaces role service, and the DFSReplication role service installed. Server1 and Server2 are part of a Distributed File System (DFS) Replication group named Group1. Server1and Server2 are separated by a low-speed WAN connection.You need to limit the amount of bandwidth that DFS can use to replicate between Server1 and Server2.

What should you modify?

A. The cache duration of the namespaceB. The staging quota of the replicated folderC. The referral ordering of the namespaceD. The schedule of the replication group

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc732278.aspx

To edit the schedule and bandwidth for a specific connection, use the following steps:In the console tree under the Replication node, select the appropriate replication group.

Click the Connections tab, right-click the connection that you want to edit, and then click Properties.

Click the Schedule tab, select Custom connection schedule and then click Edit Schedule.

Page 10: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Use the Edit Schedule dialog box to control when replication occurs, as well as the maximum amount ofbandwidth replication can consume.

QUESTION 13Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 has the File Server Resource Manager role service installed. You configure a quota threshold asshown in the exhibit. (Click the Exhibit button.)You need to ensure that a user named User1 receives an email notification when the threshold is exceeded.

What should you do?

Exhibit:

A. Configure the File Server Resource Manager Options.B. Modify the members of the Performance Log Users group.C. Create a performance counter alert.D. Create a classification rule.

Correct Answer: ASection: (none)

Page 11: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:A)http://technet.microsoft.com/en-us/library/cc756031(v=ws.10).aspx

When you create quotas and file screens, you have the option of sending e-mail notifications to users whentheir quota limit is approaching or after they have attempted to save files that have been blocked. If you want toroutinely notify certain administrators of quota and file screening events, you can configure one or more defaultrecipients.To send these notifications, you must specify the SMTP server to be used for forwarding the e-mail messages.To configure e-mail optionsIn the console tree, right-click File Server Resour ce Manager , and then click Configure options. The FileServer Resource Manager Options dialog box opens.

On the E-mail Notifications tab, under SMTP server name or IP address, type the host name or the IP addressof the SMTP server that will forward e-mail notifications.

If you want to routinely notify certain administrators of quota or file screening events, under Defaultadministrator recipients, type each e-mail address.

Use the format account@domain. Use semicolons to separate multiple accounts.

To test your settings, click Send Test E-mail.

B) Los miembros de este grupo pueden administrar los contadores de rendimiento, registros y alertas sobre loscontroladores de dominio en el dominio, a nivel local como desde clientes remotos, sin ser miembro del grupoAdministradores.No reciben por defecto notificaciones

C) Los contadores de rendimiento son mediciones del estado o de la actividad del sistema. Se pueden incluiren el sistema operativo o formar parte de aplicaciones individuales. El Monitor de rendimiento de Windowssolicita el valor actual de los contadores de rendimiento en intervalos de tiempo especificados.

D) Se usa para clasificar archivos en un file server basandose en una valor establecido

QUESTION 14Your network contains an Active Directory domain named contoso.com. The domain contains a file servernamed Server1 that runs Windows Server 2012. You view the effective policy settings of Server1 as shown in the exhibit. (Click the Exhibit button.)On Server1, you have a folder named C:\Share1 that is shared as Share1. Share1 contains confidential data. Agroup named Group1 has full control of the content in Share1. You need to ensure that an entry is added to the event log whenever a member of Group1 deletes a file inShare1.

What should you configure?

Exhibit:

Page 12: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. The Audit File System setting of Servers GPOB. The Sharing settings of C:\Share1C. The Security settings of C:\Share1D. The Audit File Share setting of Servers GPO

Correct Answer: CSection: (none)Explanation

Explanation/Reference:a) Esta configuración de directiva de seguridad determina si el usuario intenta acceder a los objetos delsistema. Los eventos de auditoría sólo se generan para los objetos que han configurado las listas de control deacceso al sistema (SACL), y sólo si el tipo de acceso solicitado (como escribir, leer o modificar) y la cuenta querealiza la solicitud coincide con la configuración de la SACL. No se puede especificar un usuario concreto,auditara a todos los usuarios.

b) No se puede crear una auditoria de acceso en la configuracion de recurso compartido

c) Se puede configurar la auditoria de acceso de un usuario en la pestaña de configuracion de permisos de

Page 13: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

seguridad. Esto hay que habilitarloTo enable folder permission auditing, you can follow the below steps:1. Click start and run "secpol.msc" without quotes.2. Open the Local Policies\Audit Policy3. Enable the Audit object access for "Success" and "Failure".4. Go to Auto Hidden files and folders, right click the folder and select properties.5. Go to Security Page and click Advanced.6. Click Auditing and Edit.7. Click add, type everyone in the Select User, Computer, or Group.8. Choose Apply onto: This folder, subfolders and files.9. Tick on the box “Change permissions” 10. Click OK.http://social.technet.microsoft.com/Forums/en-US/winservergen/thread/13779c78-0c73-4477-8014-f2eb10f3f10f/

D) Esta configuración de directiva de seguridad determina si el sistema operativo genera eventos de auditoríacuando se accede a un recurso compartido de archivos. No se puede especificar un usuario concreto, auditaraa todos los usuarios.

Los eventos de auditoría no se generan cuando se crean las acciones, eliminar, o cuando la cuota de cambiode permisos.

No hay listas de control de acceso del sistema (SACL) de acciones, por lo tanto, una vez que se habilita estaopción, el acceso a todas las partes en el sistema será auditado.

Combinado con la auditoría del sistema de archivos, recursos compartidos de archivos de auditoría permiterealizar un seguimiento de lo que se accede al contenido, la fuente (dirección IP y puerto) de la solicitud, y lacuenta de usuario que se utiliza para el acceso.

QUESTION 15You have a server named Server1 that runs Windows Server 2012. Server1 has the File Server ResourceManager role service installed. Server1 has a folder named Folder1 that is used by the human resources department.You need to ensure that an email notification is sent immediately to the human resources manager when a usercopies an audio file or a video file to Folder1.

What should you configure on Server1?

A. A file screenB. A file screen exceptionC. A file groupD. A storage report task

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc732349%28v=ws.10%29.aspx#BKMK_CreateFS

A) Con el Administrador de recursos del servidor de archivos (FSRM) se pueden crear filtros de archivos queimpiden que los usuarios guarden archivos no autorizados en los volúmenes o carpetas.Puede crear filtros de archivos para evitar que los usuarios guarden archivos no autorizados en los volúmeneso carpetas. Hay dos tipos de aplicación de la pantalla de archivo: aplicación activa y pasiva. Aplicación deanálisis de archivos activo no permite al usuario guardar un archivo no autorizado. La aplicación de analisis defiltro Pasivo a los archivos permite al usuario guardar el archivo, pero avisa a l usuario de que el archivono es un archivo autorizado. Puede configurar las n otificaciones, como los eventos registrados en elregistro de eventos o mensajes de correo electrónic o enviado a los usuarios y administradores , en el

Page 14: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

marco de la aplicación de análisis de archivos activo y pasivo. (file screen enforcement.)http://technet.microsoft.com/en-us/library/cc734419%28v=ws.10%29.aspx

B) A veces hay que aplicar excepciones al filtro de archivos , por ejemplo en un filtrado activo de archivosde video puede ser necesario permitir que un grupo pueda guardarlos por ser parte de su trabajo.Una excepción al filtro de archivos es un tipo especial de filtro de archivos que anula cualquier filtrado dearchivos que de otra aplicación a una carpeta y todas sus subcarpetas en una ruta de excepción designada. Esdecir, se crea una excepción a las normas derivadas de una carpeta principal.NOTA: No se puede crear una file screen exception en una carpeta principal en la que ya hay un File screen,habra que crearlo en una subcarpeta o modificar el File screen.http://technet.microsoft.com/en-us/library/cc730822.aspx

C)Un grupo de archivos se utiliza para definir un espacio de nombres para una File Sreen, excepción alfiltro de file screen exception, o Files by File Gr oup storage report . Consiste en un conjunto depatrones de nombres de archivo, que se agrupan por lo siguiente:

Archivos para incluir: Archivos que pertenecen al grupo

Archivos que se excluyen: Archivos que no pert enecen en el grupo

Para mayor comodidad, puede crear y editar grupos de archivos durante la edición de las propiedades de FileSreen, excepción al filtro de file screen exception, o Files by File Group storage report.. Cualquier grupo decambios en los archivos que se realicen a partir de estas hojas de propiedades no se limitan al elemento actualque está trabajando.http://technet.microsoft.com/en-us/library/cc770594.aspx

D)En el nodo Storage Reports Management, puede realizar las siguientes tareas:

- Programar informes de almacenamiento periódicos que le permiten identificar las tendencias en el uso deldisco.

- Monitorizar intentos de guardar archivos no autorizados para todos los usuarios o un grupo seleccionadode usuarios.

- Generar informes de almacenamiento al instante.

Para configurar las notificaciones de correo electr ónico y algunas capacidades de informes, primerodebe configurar las opciones del File Server Resource Manager .:

To configure e-mail options

In the console tree, right-click File Server Resource Manager, and then click Configure Options. The FileServer Resource Manager Options dialog box opens.

On the E-mail Notifications tab, under SMTP server name or IP address, type the host name or the IPaddress of the SMTP server that will forward e-mail notifications and storage reports.

If you want to routinely notify certain administrators about quota or file screening events or e-mail storagereports, under Default administrator recipients, type each e-mail address.

Use the format account@domain. Use semicolons to separate multiple accounts.

To specify a different "From" address for e-mail notifications and storage reports sent from File ServerResource Manager, under Default "From" e-mail address, type the e-mail address that you want to appear inyour message.

To test your settings, click Send Test E-mail.

Click OK.

Page 15: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

http://technet.microsoft.com/en-us/library/cc771212.aspx

QUESTION 16Your network contains an Active Directory domain named adatum.com. The domain contains five servers. The servers are configured as shown in the following table.

All desktop computers in adatum.com run Windows 8 and are configured to use BitLocker Drive Encryption(BitLocker) on all local disk drives.You need to deploy the Network Unlock feature.The solution must minimize the number of features and server roles installed on the network.

To which server should you deploy the feature

A. DC1B. DC2C. Server1D. Server2

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 17Your network contains an Active Directory domain named contoso.com. The domain contains two serversnamed Server1 and Server2. Both servers run Windows Server 2012. Both servers have the File and StorageServices server role, the DFS Namespace role service, and the DFS Replication role service installed.

Server1 and Server2 are part of a Distributed File System (DFS) Replication group named Group1. Server1and Server2 are connected by using a high-speed LAN connection.

You need to minimize the amount of processor resources consumed by DFS Replication.

What should you do?

A. Reduce the bandwidth usage.B. Disable Remote Differential Compression (RDC).C. Modify the staging quota.D. Modify the replication schedule.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation:

Page 16: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

B. Because disabling RDC can help conserve disk input/output (I/O) and CPU resources, you might want todisable RDC on a connection if the sending and rece iving members are in a local area network (LAN) ,and bandwidth use is not a concern . However, in a LAN environment where bandwidth is contended, RDCcan be beneficial when transferring large files.

En nuestro caso la conectividad es de alta velocidad http://technet.microsoft.com/en-us/library/cc758825%28v=ws.10%29.aspx

C.DFS Replication uses staging folders for each replicated folder to act as caches for new and changed files thatare ready to be replicated from sending members to receiving members. These files are stored under the localpath of the replicated folder in the DfsrPrivate\Staging folder. If a staging folder quota is too small, DFS Replication might consume additional CPU and disk resources, andreplication might slow down or even stop. By default, the quota size of each staging folder is 4,096 MB, and the quota size of each Conflict and Deletedfolder is 660 MB. The size of each folder on a member is cumulative per volume, so if there are multiplereplicated folders on a member, DFS Replication creates multiple staging and Conflict and Deleted folders,each with its own quota.

Aqui no se menciona nada de que la replicacion este siendo lenta ni que se este parando.http://technet.microsoft.com/en-us/library/cc754229.aspx

QUESTION 18Your company has a main office and two branch offices. The main office is located in New York. The branchoffices are located in Seattle and Chicago.

The network contains an Active Directory domain named contoso.com. An Active Directory site exists for eachoffice. Active Directory site links exist between the main office and the branch offices. All servers run WindowsServer 2012.

The domain contains three file servers. The file servers are configured as shown in the following table.

You implement a Distributed File System (DFS) replication group named ReplGroup.

ReplGroup is used to replicate a folder on each file server. ReplGroup uses a hub and spoke topology. NYC-SVR1 is configured as the hub server.

You need to ensure that replication can occur if NYC-SVR1 fails.

What should you do?

A. Create an Active Directory site link.B. Modify the properties of ReplGroup.C. Create an Active Directory site link bridge.D. Create a connection in ReplGroup.

Correct Answer: DSection: (none)Explanation

Page 17: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:Explanation:

QUESTION 19You have a server named Server1 that runs Windows Server 2012. On Server1, you configure a custom DataCollector Set (DCS) named DCS1. DCS1 is configured to store performance log data in C:\Logs.You need to ensure that the contents of C:\Logs are deleted automatically when the folder reaches 100 MB insize.

What should you configure?

A. A File Server Resource Manager (FSRM) quota on the C:\Logs folderB. A File Server Resource Manager (FSRM) file screen on the C:\Logs folderC. A schedule for DCS1D. The Data Manager settings of DCS1

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://sourcedaddy.com/windows-7/using-data-manager-view-performance-data.html

QUESTION 20Your domain has contains a Windows 8 computer name Computer1 using BitLocker. The E:\ drive is encryptedand currently locked.

You need to unlock the E:\ drive with the recovery key stored on C:\

What should you run?

A. Unlock-BitLockerB. Suspend-BitLockerC. Enable-BitLockerAutoUnlocD. Disable-BitLocker

Correct Answer: ASection: (none)Explanation

Explanation/Reference:A. Restores access to data on a BitLocker volume.

http://technet.microsoft.com/en-us/library/jj649833(v=wps.620).aspx

QUESTION 21Your network contains and active Directory domain named contoso.com. The doman contains a server namedServer1 that runs Windows Server 2012A local account named Admin1 is a member of the Administrators group on Server1.You need to generate an audit event whenever Admin1 is denied access to a file or folder.What should you run?

A. auditpol.exe /set /user:admin1 /category:"detailed tracking" /failure:enableB. auditpol.exe /set/user:admin1 /failure:enable

Page 18: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

C. auditpol.exe /resourcesacl /set /type:keyauditpol.e xe /resourcesacl /set /type: /access:gaD. auditpol.exe /resourcesacl /set /type:file /user:ad min1 /failure

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/ff625687.aspx set a global resource SACL to audit successful and failed attempts by a user to perform generic read and writefunctions on files or folders:auditpol /resourceSACL /set /type:File /user:MYDOMA INmyuser /success /failure /access:FRFW

http://technet.microsoft.com/en-us/library/ff625687%28v=ws.10%29.aspx

QUESTION 22Your network contains and Ctive Directory domain named contoso.com.The domain contains a file servernamed server1 that runs windows Server 2012.You view the effective policy settings of server1 as shown in the exhibit.You need to ensure that an entry is added to the event log whenever a local user account is created or deletedon server1.What should you do?

A. I Servers GPO, modify the Advanced Audit Configuration SettingsB. On Server1, attach a task to the security logC. In Servers GPO, modify the Audit Policy settingsD. On Server1, attach a task to the system log.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://blogs.technet.com/b/abizerh/archive/2010/05/27/tracing-down-user-and-computer-account-deletion-in-active-directory.aspx

http://technet.microsoft.com/en-us/library/jj852202(v=ws.10).aspxAudit Policy settings-Any changes to user account and resource permissions. -Any failed attempts for user logon. -Any failed attempts for resource access. -Any modification to the system files.

Advanced Audit Configuration Settingsaudit compliance with important business-related and security-related rules by tracking precisely defined activities, such as:

-A group administrator has modified settings or data on servers thatcontain finance information. -An employee within a defined group has accessed an important file. -The correct system access control list (SACL) is applied to everyfile and folder or registry key on a computer or file share as averifiable safeguardagainst undetected access.

http://technet.microsoft.com/en-us/library/dd772623%28v=ws.10%29.aspx. In Servers GPO, modify the Audit Policy settings - enabling audit account management setting will generate

Page 19: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

events about account creation, deletion and so on.

QUESTION 23On the DFS replication your receive a wrap error on the sysvol on domain controller 4.Which 3 steps should you do to recover this error in the correct order.

A. Stop FSR B. Start FSR C. Edit the computer object in ADD. Edit the registryE. Stop DFSRF. Start DFRS

Correct Answer: ABDSection: (none)Explanation

Explanation/Reference:http://support.microsoft.com/kb/292438/en-us

http://blogs.technet.com/b/instan/archive/2009/07/14/what-happens-in-a-journal-wrap.aspx

QUESTION 24Your network contains an Active Directory domain named contoso.com. The domain functional level isWindows Server 2008. All domain controllers run Windows Server 2008 R2.

The domain contains a file server named Server1 that runs Windows Server 2012.

Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive. Server1 uses a Trusted Platform Module(TPM) chip.

You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policyobject (GPO).

You need to ensure that you can back up the BitLocker recovery information to Active Directory.

Page 20: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

What should you do?

A. Raise the forest functional level to Windows Server 2008 R2.B. Enable the Configure the level of TPM owner authorization information available to the operating system

policy setting and set the Operating system managed TPM authentication level to None.C. Add a BitLocker data recovery agent.D. Import the TpmSchemaExtension.ldf and TpmSchemaExtensionACLChanges.ldf schema extensions to the

Active Directory schema.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:Explanation:http://technet.microsoft.com/es-es/library/jj592683.aspx#BKMK_provhttp://technet.microsoft.com/en-us/library/jj592683.aspx#BKMK_addscons

For Windows 8 a change to how the TPM owner authorization value is stored in AD DS was implemented in theAD DS schema. The TPM owner authorization value is now stored in a separate object which is linked to theComputer object. This value was stored as a property in the Computer object itself for the default WindowsServer 2008 R2 schemas. Windows Server 2012 domain controllers have the default schema to backup TPMowner authorization information in the separate object. If you are not upgrading your domain controller toWindows Server 2012 you need to extend the schema to support this change. If Active Directory backup of theTPM owner authorization value is enabled in a Windows Server 2008 R2 environment without extending theschema, the TPM provisioning will fail and the TPM will remain in a Not Ready state for computers runningWindows 8....

... To support Windows 8 computers that are managed by a Windows Server 2003 or Windows 2008domain controller

There are two schema extensions that you can copy down and add to your AD DS schema:

TpmSchemaExtension.ldf

This schema extension brings parity with the Windows Server 2012 schema. With this change, the TPMowner authorization information is stored in a separate TPM object linked to the corresponding computerobject. Only the Computer object that has created the TPM object can update it. This means that anysubsequent updates to the TPM objects will not succeed in dual boot scenarios or scenarios where thecomputer is reimaged resulting in a new AD computer object being created. To support such scenarios, anupdate to the schema was created.

TpmSchemaExtensionACLChanges.ldf

This schema update modifies the ACLs on the TPM object to be less restrictive so that any subsequentoperating system which takes ownership of the computer object can update the owner authorization value in ADDS. However, this is less secure as any computer in the domain can now update the OwnerAuth of the TPMobject (although it cannot read the OwnerAuth) and DOS attacks can be made from within the enterprise. Therecommended mitigation in such a scenario is to do regular backup of TPM objects and enable auditing to trackchanges for these objects.

QUESTION 25Your network contains an Active Directory domain named contoso.com. The domain contains a Web servernamed www.contoso.com. The Web server is available on the Internet. You implement DirectAccess by using the default configuration.You need to ensure that users never attempt to connect to www.contoso.com by using DirectAccess.The solution must not prevent the users from using DirectAccess to access other resources in contoso.com.

Page 21: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which settings should you configure in a Group Policy object (GPO)?

A. Name Resolution PolicyB. DNS ClientC. Network ConnectionsD. DirectAccess Client Experience Settings

Correct Answer: ASection: (none)Explanation

Explanation/Reference:For DirectAccess, the NRPT must be configured with the namespaces of your intranet with a leading dot (forexample, .internal.contoso.com or .corp.contoso.com). For a DirectAccess client, any name request thatmatches one of these namespaces will be sent to the specified intranet Domain Name System (DNS) servers.Include all intranet DNS namespaces that you want DirectAccess client computers to access. There are no command line methods for configuring NRPT rules. You must use Group Policy settings. Toconfigure the NRPT through Group Policy, use the Group Policy add-in at Computer Configuration\Policies\Windows Settings\Name Resolution Policy in the Group Policy object for DirectAccess clients. You cancreate a new NRPT rule and edit or delete existing rules. For more information, see Configure the NRPT withGroup Policy.

QUESTION 26You have a DNS server named Server1. Server1 has a primary zone named contoso.com. Zone Aging/Scavenging is configured for the contoso.com zone. One month ago, an Administrator removed a server named Server2 from the network. You discover that astatic resource record for Server2 is present in contoso.com. Resource records for decommissioned client computers are removed automatically from contoso.com.You need to ensure that the static resource records for all of the servers are removed automatically fromcontoso.com.

What should you modify?

A. The Security settings of the static resource recordsB. The Expires after value of contoso.comC. The Record time stamp value of the static resource recordsD. The time-to-live (TTL) value of the static resource records

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 27Your network contains two Active Directory domains named contoso.com and adatum.com. The networkcontains a server named Server1 that runs Windows Server 2012. Server1 has the DNS Server server role installed. Server1 has a copy of the contoso.com DNS zone.You need to configure Server1 to resolve names in the adatum.com domain.The solution must meet the following requirements: · Prevent the need to change the configuration of the current name servers that host zones for adatum.com. · Minimize Administrative effort.

Which type of zone should you create?

A. Primary

Page 22: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

B. SecondaryC. Reverse lookupD. Stub

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 28Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 andhave the DNS Server server role installed. On Server1, you create a standard primary zone named contoso.com.You need to ensure that Server2 can host a secondary zone for contoso.com.

What should you do from Server1?

A. Add Server2 as a name server.B. Convert contoso.com to an Active Directory-integrated zone.C. Create a zone delegation that points to Server2.D. Create a trust anchor named Server2.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc770984.aspx

QUESTION 29You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed. On Server1, you create a network policy named Policy1.You need to configure Policy1 to apply only to VPN connections that use the L2TP protocol.

What should you configure in Policy1?

A. The Tunnel TypeB. The Service TypeC. The NAS Port TypeD. The Framed Protocol

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

Page 23: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 30Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that runs Windows Server 2012. All client computers run Windows 8 Enterprise. DC1 contains a Group Policy object (GPO) named GPO1.You need to deploy a VPN connection to all users.

What should you configure from User Configuration in GPO1?

A. Preferences/Control Panel Settings/Network OptionsB. Policies/Administrative Templates/Windows Components/Windows Mobility CenterC. Policies/Administrative Templates/Network/Windows Connect NowD. Policies/Administrative Templates/Network/Network Connections

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc772449.aspx

QUESTION 31Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012.All sales users have laptop computers that run Windows 8. The sales computers are joined to the domain. All user accounts for the sales department are in anorganizational unit (OU) named Sales_OU. A Group Policy object (GPO) named GPO1 is linked to Sales_OU.You need to configure a dial-up connection for all of the sales users.

What should you configure from User Configuration in GPO1?

A. Policies/Administrative Templates/Network/Windows Connect NowB. Policies/Administrative Templates/Windows Components/Windows Mobility CenterC. Preferences/Control Panel Settings/Network OptionsD. Policies/Administrative Templates/Network/Network Connections

Page 24: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc772107.aspx

To create a new Dial-Up Connection preference itemOpen the Group Policy Management Console. Right-click the Group Policy object (GPO) that should containthe new preference item, and then click Edit.In the console tree under Computer Configuration or User Configuration, expand the Preferences folder, andthen expand the Control Panel Settings folder.Right-click the Network Options node, point to New, and select Dial-Up Connection.

QUESTION 32You have a server named Server1 that runs Windows Server 2012. Server1 has 2 dual-core processors and 16GB of RAM.You install the Hyper-V server role in Server1.You plan to create two virtual machines on Server1.You need to ensure that both virtual machines can use up to 8 GB of memory. The solution must ensure thatboth virtual machines can be started simultaneously.

What should you configure on each virtual machine?

A. Dynamic MemoryB. NUMA topologyC. Memory weight

Page 25: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

D. Ressource Control"First Test, First Pass" - www.lead2pass.com 125Microsoft 70-411 Exam

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 33Your network contains an Active Directory domain named corp.contoso.com. The domain contains a domaincontroller named DC1. When you run ping dcl.corp.contoso.com, you receive the result as shown in the exhibit.(Click the Exhibit button.)

You need to ensure that DC1 can respond to the Ping command.

Which rule should you modify? To answer, select the appropriate rule in the answer area.

Page 26: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A.B.C.D.

Correct Answer: Section: (none)Explanation

Explanation/Reference:"First Test, First Pass" - www.lead2pass.com 126Microsoft 70-411 Exam

QUESTION 34You have a server named Server1 that runs Windows Server 2012.You promote Server1 to domain controller.You need to view the service location (SVR) records that Server1 registers on DNS.

What should you do on Server1?

Page 27: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Open the Srv.sys fileB. Open the Netlogon.dns fileC. Run ipconfig/displaydnsD. Run Get-DnsServerDiagnostics

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 35Your company has a remote office that contains 600 client computers on a single subnet. You need to select asubnet mask for the network that will support all of the client computers. The solution must minimize thenumber of unused addresses.Which subnet mask should you select?

A. 255.255.252.0B. 255.255.254.0C. 255.255.255.0D. 255.255.255.128

Correct Answer: ASection: (none)Explanation

Explanation/Reference:"First Test, First Pass" - www.lead2pass.com 127About Lead2pass.com

Lead2pass.com was founded in 2006. We provide latest & high quality IT Certification Training ExamQuestions, Study Guides, Practice Tests. Lead the way to help you pass any IT Certification exams, 100%Pass Guaranteed or Full Refund. Especially Cisco, CompTIA, Citrix, EMC, HP, Oracle, VMware, Juniper,Check Point, LPI, Nortel, EXIN and so on.

Our Slogan: First Test, First Pass.

Help you to pass any IT Certification exams at the first try.

You can reach us at any of the email addresses listed below.

Sales: [email protected]

Support: [email protected]

Technical Assistance Center: [email protected]

Any problems about IT certification or our products, you could rely upon us, we will give you satisfactoryanswers in 24 hours.

Our Official: http://www.lead2pass.com

QUESTION 36Full list of URL's used as Reference

A.

Page 28: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

B.C.D.

Correct Answer: Section: (none)Explanation

Explanation/Reference:

Page 29: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that
Page 30: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 37Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 has the DHCP Server server role installed.

The network contains 400 client computers that run Windows 8. All of the client computers are joined to thedomain and are configured DHCP clients.

You install a new server named Server2 that runs Windows Server 2012.

On Server2, you install the Network Policy Server role service and you configure Network Access Protection(NAP) to use the DHCP enforcement method.

You need to ensure that Server1 only provides a valid default gateway to computers that pass the systemhealth validation.

Which two actions should you perform? (Each correct answer presents part of the solution.Choose two.)

A. From the DHCP console, configure the 016 Swap Server option.B. From the DHCP console, create a new policy.C. From the NAP Client Configuration console, enable the DHCP Quarantine Enforcement Client.D. From the DHCP console, enable NAP on all scopes.E. From Server Manager, install the Network Policy Server role service.

Correct Answer: DESection: (none)Explanation

Explanation/Reference:Explanation: D: The administrator must define the following settings on the NAP DHCP server:/ (D) NAP-enabled scopes: In order to use a DHCP scope with NAP, you must enable it specifically for NAP inscope properties under NAP settings.

/ Default NAP class: You must configure any required scope options for computers that are noncompliant withhealth requirements. A default gateway is not provided to noncompliant computers regardless of whether the003 Router option is configured here. / Remote RADIUS server groups: If connection requests are forwardedfrom the DHCP server to a NAP health policy server on another computer, you must configure the NPS serviceon the NAP DHCP server to forward connection requests to the NAP health policy server. This setting is notrequired if the NAP DHCP server is also the NAP health policy server.

/ Default user class: You must configure any required scope options for computers that are compliant withhealth requirements.The NAP DHCP server is a server running Windows Server 2008 or Windows Server 2008 R2 (or Windows2012) with the DHCP server role installed and running. Additionally, if this server is not also the NAP healthpolicy server, it must have the NPS role service installed (E), running, and configured to forward connectionrequests to the NAP health policy server. The NAP DHCP server restricts noncompliant client access byproviding a limited IP address configuration to computers that do not meet health requirements. A limitedaccess configuration has a subnet mask of 255.255.255.255 and no default gateway. Static host routes areprovisioned to provide access to the DHCP server and any servers that have been added to remediation servergroups on the NAP health policy server.

Reference: DHCP Enforcement Configuration

QUESTION 38Your network is configured as shown in the exhibit. (Click the Exhibit button.)

Page 31: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Server1 regularly accesses Server2.

You discover that all of the connections from Server1 to Server2 are routed through Router1.

You need to optimize the connection path from Server1 to Server2.

Which route command should you run on Server1?

A. Route add -p 10.10.10.0 MASK 255.255.255.0 10.10.10.1 METRIC 50B. Route add -p 10.10.10.0 MASK 255.255.255.0 172.23.16.2 METRIC 100C. Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.1 METRIC 100D. Route add -p 10.10.10.12 MASK 255.255.255.0 10.10.10.0 METRIC 50

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 39Your network contains an Active Directory domain named adatum.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and as a DHCP server.You need to ensure that only computers that send a statement of health are checked for Network AccessProtection (NAP) health requirements.

Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

A. The Called Station ID constraintsB. The MS-Service Class conditionsC. The Health Policies conditionsD. The NAS Port Type constraintsE. The NAP-Capable Computers conditions

Correct Answer: CESection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc731560.aspx

Page 32: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 40Your network contains two Active Directory forests named adatum.com and contoso.com. The networkcontains three servers. The servers are configured as shown in the following table.

You need to ensure that connection requests from adatum.com users are forwarded to Server2 and connectionrequests from contoso.com users are forwarded to Server3.

Which two should you configure in the connection request policies on Server1? (Each correct answer presentspart of the solution. Choose two.)

A. The Authentication settingsB. The User Name conditionC. The Standard RADIUS Attributes settingsD. The Identity Type conditionE. The Location Groups condition

Correct Answer: ABSection: (none)Explanation

Explanation/Reference:Explanation: A: A connection request policy profile is a set of properties that are applied to an incomingRADIUS message. A connection request policy profile consists of the following groups of properties:/ AuthenticationYou can set the following authentication options that are used for RADIUS Access-Request messages:// Authenticate requests on this server.// Forward requests to another RADIUS server in a remote RADIUS server group. // Accept the connectionattempt without performing authentication or authorization./ Accounting/ Attribute manipulation/ Advanced

B: * A connection request policy is a named rule that consists of the following elements:/ Conditions/ Profile

* The User-Name RADIUS attribute is a character string that typically contains a user account location and auser account name. The user account location is also called the realm or realm name, and is synonymous withthe concept of domain, including DNS domains, Active Directory domains, and Windows NT 4.0 domains

Note:* NPS as a RADIUS proxy

The default connection request policy is deleted, and two new connection request policies are created toforward requests to two different domains. In this example, NPS is configured as a RADIUS proxy. NPS does

Page 33: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

not process any connection requests on the local server. Instead, it forwards connection requests to NPS orother RADIUS servers that are configured as members of remote RADIUS server groups.

QUESTION 41Your network contains two Active Directory forests named adatum.com and contoso.com. The networkcontains three servers. The servers are configured as shown in the following table.

You need to ensure that connection requests from adatum.com users are forwarded to Server2 and connectionrequests from contoso.com users are forwarded to Server3.

Which two should you configure in the connection request policies on Server1? (Each correct answer presentspart of the solution. Choose two.)

A. The Standard RADIUS Attributes settingsB. The Location Groups conditionC. The User Name conditionD. The Identity Type conditionE. The Authentication settings

Correct Answer: CESection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc757328.aspx

QUESTION 42You have installed Routing and Remote Access on Server1 what should you configure next to use it as a NATserver.

A. Add New InterfaceB. Create Static RouteC. Configure the IPv4 DHCP Relay Agent D. Configure the IPv6 DHCP Relay Agent

Correct Answer: ASection: (none)Explanation

Explanation/Reference:A. Network address translation (NAT) allows you to share a connection to the public Internet through a singleinterface with a single public IP address. The computers on the private network use private, non-routableaddresses. NAT maps the private addresses to the public address.http://technet.microsoft.com/en-us/library/dd469812.aspx

Page 34: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 43Your network contains four Network Policy Server (NPS) servers named Server1, Server2, Server3, andServer4.Server1 is configured as a RADIUS proxy that forwards connection request to a remote RADIUS server groupnamed Group1.You need to ensure that Server2 and Server3 receitve connection requests. Server4 must only receiveconnection requests if both Server2 and Server3 are unavailable.How should you configrure Group1?

A. Change the Weight of Server2 and Server3 to 10B. Change the Weight of Server4 to 10C. Change the Priority of Server2 and Server3 to 10D. Change the Priority of Server4 to 10

Correct Answer: DSection: (none)Explanation

Explanation/Reference:The default priority is 1 and can be changed from 1 to 65535. So changing server 2 and 3 to priority 10 is theway to go.

"Priority. Priority specifies the order of importance of the RADIUS server to the NPS proxy server. Priority levelmust be assigned a value that is an integer, such as 1, 2, or 3. The lower the number, the higher priority theNPS proxy gives to the RADIUS server. For example, if the RADIUS server is assigned the highest priority of 1,the NPS proxy sends connection requests to the RADIUS server first; if servers with priority 1 are not available,NPS then sends connection requests to RADIUS servers with priority 2, and so on"

Explanation:During the NPS proxy configuration process, you can create remote RADIUS server groups and then addRADIUS servers to each group. To configure load balancing, you must have more than one RADIUS server perremote RADIUS server group. While adding group members, or after creating a RADIUS server as a groupmember, you can access the Add RADIUS server dialog box to configure the following items on the LoadBalancing tab:

Priority . Priority specifies the order of importance of the RADIUS server to the NPS proxy server. Priority levelmust be assigned a value that is an integer, such as 1, 2, or 3. The lower the number, the higher priority theNPS proxy gives to the RADIUS server. For example, if the RADIUS server is assigned the highest priority of 1,the NPS proxy sends connection requests to the RADIUS server first; if servers with priority 1 are not available,NPS then sends connection requests to RADIUS servers with priority 2, and so on. You can assign the samepriority to multiple RADIUS servers, and then use the Weight setting to load balance between them.

Weight . NPS uses this Weight setting to determine how many connection requests to send to each groupmember when the group members have the same priority level. Weight setting must be assigned a valuebetween 1 and 100, and the value represents a percentage of 100 percent. For example, if the remote RADIUSserver group contains two members that both have a priority level of 1 and a weight rating of 50, the NPS proxyforwards 50 percent of the connection requests to each RADIUS server.

Advanced settings . These failover settings provide a way for NPS to determine whether the remote RADIUSserver is unavailable. If NPS determines that a RADIUS server is unavailable, it can start sending connectionrequests to other group members. With these settings you can configure the number of seconds that the NPSproxy waits for a response from the RADIUS server before it considers the request dropped; the maximumnumber of dropped requests before the NPS proxy identifies the RADIUS server as unavailable; and thenumber of seconds that can elapse between requests before the NPS proxy identifies the RADIUS server asunavailable.

Reference: http://technet.microsoft.com/en-us/library/dd197433(WS.10).aspx

Page 35: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 44Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012.The domain contains two servers. The servers are configured as shown in the following table.

All client computers run Windows 8 Enterprise. You plan to deploy Network Access Protection (NAP) by usingIPSec enforcement. A Group Policy object (GPO) named GPO1 is configured to deploy a trusted server groupto all of the client computers.You need to ensure that the client computers can discover HRA servers automatically.

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A. On DC1, create a service location (SRV) record.B. On Server2, configure the EnableDiscovery registry key.C. On all of the client computers, configure the EnableDiscovery registry key.D. In a GPO, modify the Request Policy setting for the NAP Client Configuration.E. On Dc1, create an alias (CNAME) record.

Correct Answer: ACDSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd296901.aspx

QUESTION 45Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 has the Network Policy Server role service installed. You plan to configure Server1 as a Network Access Protection (NAP) health policy server for VPN enforcementby using the Configure NAP wizard.You need to ensure that you can configure the VPN enforcement method on Server1 successfully.

What should you install on Server1 before you run the Configure NAP wizard?

A. The Host Credential Authorization Protocol (HCAP)B. A system health validator (SHV)C. The Remote Access server roleD. A Computer certificate

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

Page 36: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 46You deploy two servers named Server1 and Server2. You install Network Policy Server (NPS) on both servers.On Server1, you configure the following NPS settings: · RADIUS Clients · Network Policies · Connection Request Policies · SQL Server Logging PropertiesYou export the NPS configurations to a file and import the file to Server2.You need to ensure that the NPS configurations on Server2 are the same as the NPS configurations onServer1.

Which settings should you manually configure on Server2?

A. SQL Server Logging PropertiesB. Connection Request PoliciesC. RADIUS ClientsD. Network Policies

Correct Answer: ASection: (none)Explanation

Explanation/Reference:If SQL Server logging is configured on the source NPS server, SQL Server logging settings are not exported tothe XML file. After you import the file on another NPS server, you must manually configure SQL Server logging.

QUESTION 47Your network contains an Active Directory domain named contoso.com. The domain contains a RADIUS servernamed Server1 that runs Windows Server 2012.You add a VPN server named Server2 to the network.On Server1, you create several network policies.You need to configure Server1 to accept authentication requests from Server2.

http://www.gratisexam.com/

Which tool should you use on Server1?

A. Connection Manager Administration Kit (CMAK).B. Routing and Remote AccessC. Network Policy Server (NPS)D. Set-RemoteAccessRadius

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://www.youtube.com/watch?v=0_1GOBTL4FE

QUESTION 48Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1.

Page 37: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Server1 has the DHCP Server server role and the Network Policy Server role service installed. Server1 contains three non-overlapping scopes named Scope1, Scope2, and Scope3. Server1 currently provides the same Network Access Protection (NAP) settings to the three scopes. You modify the settings of Scope1 as shown in the exhibit. (Click the Exhibit button.)You need to configure Server1 to provide unique NAP enforcement settings to the NAP non- compliant DHCPclients from Scope1.

What should you create?

Exhibit:

A. A network policy that has the MS-Service Class conditionB. A network policy that has the Identity Type conditionC. A connection request policy that has the Identity Type conditionD. A connection request policy that has the Service Type condition

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc731560(v=ws.10).aspx

Open the NPS console, double-click Policies , click Network Policies , and then double-click the policy youwant to configure.In policy Properties , click the Conditions tab , and then click Add . In Select condition , scroll to the Network

Page 38: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Access Protection group of conditions.If you want to configure the Identity Type condition, click Identity Type, and then click Add. In Specifythe method in which clients are identified in this policy, select the items appropriate for your deployment, andthen click OK.

The Identity Type condition is used for the DHCP and Internet Protocol security (IPsec) enforcement methodsto allow client health checks when NPS does not receive an Access-Request message that contains a value forthe User-Name attribute; in this case, client health checks are performed, but authentication and authorizationare not performed.

If you want to configure the MS-Service Class condi tion, click MS-Service Class, and then click Add . InSpecify the profile namIe that identifies your DHCP scope, type the name of an existing DHCP profile, and thenclick Add.

The MS-Service Class condition restricts the policy to clients that have received an IP address from a DHCPscope that matches the specified DHCP profile name. This condition is used only when you are deployingNAP with the DHCP enforcement method .

http://technet.microsoft.com/en-us/library/cc731220(v=ws.10).aspx

QUESTION 49Your network contains an Active Directory domain named adatum.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and asa DHCP server.

You need to log all DHCP clients that have Windows Firewall disabled.

Which three actions should you perform in sequence?

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

A. Create a connection request policy B. Create Network Policy C. Create remediation server group D. Create Windows Security Health Validator (VSHV) E. Create a health Policy

Correct Answer: BDESection: (none)Explanation

Explanation/Reference:you don´t need create a Remediation server because you only need enabling NAP in reporting mode only

Con la Network Policy se especifica que se hace cuando no se cumplen las condiciones de seguridad, eneste caso se especifica que tiene que configurar para reporting Modehttp://technet.microsoft.com/es-es/library/dd314198%28v=ws.10%29.aspx

En el Windows Security Health Validator se especifica el control de validacion, en este caso Firewallhabilitadohttp://technet.microsoft.com/es-es/magazine/2009.05.goat.aspx

Con la Health Policy se elige el Security Health Validator que se va a utilizar, se elige si habraautoremediacion y que se hace con los clientes que no pueden verificarse ni positivamente ni negativamente

Page 39: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

http://technet.microsoft.com/es-es/library/dd314173%28v=ws.10%29.aspx

QUESTION 50Your network contains an Active Directory domain named contoso.com. The domain contains 2 WSUS servers,ServerA and ServerB. ServerB is a replica server of ServerA.

You need to configure WSUS to report data from SERVERB to SERVERA

What should you configure?

A. Update ReportsB. SynchronizationC. Computer GroupsD. Reporting Rollup

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

D. You can use Reports in Windows Server Update Services (WSUS) 3.0 SP2 to monitor the WSUS network,including updates, client computers, and downstream servers. If a WSUS server has replica servers, you canroll up client status information for the replica servers to the upstream server.

http://technet.microsoft.com/en-us/library/dd939891(v=ws.10).aspx

QUESTION 51Your network contains and Active Directory domain named contoso.com. The domain contains a memberserver named Server1. All servers run Server 2012.You need to collect the error events from all the servers on Server1. The solution ensure that when new servers are added to the domain, their error events are collectedautomatically on Server1.

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A. On Server1, create a source computer initiated subscription.B. From a Group Policy object (GPO), configure the Configure forwarder resource usage settings.C. From a Group Policy object (GPO), configure the Configure target Subscription Manager settingsD. On Server1, create a collector initiated subscription.

Correct Answer: ACSection: (none)Explanation

Explanation/Reference:http://msdn.microsoft.com/en-us/library/windows/desktop/bb870973(v=vs.85).aspx

QUESTION 52You have Windows Server 2012 installation media that contains a file named Install.wim. You need to identifywhich images are present in Install.wim.

What should you do?

A. Run imagex.exe and specify the/verify parameter.

Page 40: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

B. Run imagex.exe and specify the /ref parameter.C. Run dism.exe and specify the /get-mountedwiminfo parameter.D. Run dism.exe and specify the /get-imageinfo parameter.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/hh825224.aspxhttp://technet.microsoft.com/en-us/library/hh825258.aspx

Option: /Get-MountedImageInfoLists the images that are currently mounted and information about the mounted image such as whether theimage is valid, read/write permissions, mount location, mounted file path, and mounted image index.Example:Dism /Get-MountedImageInfo

Option: /Get-ImageInfoArguments:/ImageFile:<path_to_image.wim>[{/Index:<Image_index> | /Name:<Image_name>}]Displays information about the images that are contained in the .wim, vhd or .vhdx file. When used with the /Index or /Name argument, information about the specified image is displayed. The /Name argument does notapply to VHD files. You must specify /Index:1 for VHD files.Example:Dism /Get-ImageInfo /ImageFile:C:\test\offline\install.wimDism /Get-ImageInfo /ImageFile:C:\test\images\myimage.vhd /Index:1

QUESTION 53Your network contains an Active Directory domain named contoso.com. The domain contains two memberservers named Server1 and Server2. All servers run Windows Server 2012. Server1 and Server2 are nodes in a Hyper-V cluster named Cluster1.Cluster1 hosts 10 virtual machines. All of the virtual machines run Windows Server 2012 and are members of the domain. You need to ensure that the first time a service named Service1 fails on a virtual machine, the virtual machineis moved to a different node. You configure Service1 to be monitored from Failover Cluster Manager.

What should you configure on the virtual machine?

A. From the Recovery settings of Service1, set the First failure recovery action to Restart the Service.B. From the General settings, modify the Service status.C. From the Recovery settings of Service1, set the First failure recovery action to Take No Action.D. From the General settings, modify the Startup type.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 54Your network contains two servers named Server1 and Server2 that run Windows Server 2012. Server1 andServer2 have the Windows Server Update Services server role installed.

Server1 synchronizes from Microsoft Update. Server2 is a Windows Server Update Services (WSUS) replica of

Page 41: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Server1.

You need to configure replica downstream servers to send Server1 summary information about the computerupdate status.

What should you do?

A. From Server1, configure Reporting Rollup.B. From Server2, configure Reporting Rollup.C. From Server1, configure Email Notifications.D. From Server2, configure Email Notifications.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:Explanation:

WSUS Reporting Rollup Sample Tool

This tool uses the WSUS application programming interface (API) to demonstrate centralized monitoring andreporting for WSUS. It creates a single report of update and computer status from the WSUS servers into yourWSUS environment. The sample package also contains sample source files to customize or extend the toolfunctionality of the tool to meet specific needs. The WSUS Reporting Rollup Sample Tool and files are providedAS IS. No product support is available for this tool or sample files. For more information read the readme file.

http://technet.microsoft.com/en-us/windowsserver/bb466192.aspx

QUESTION 55Your network contains an Active Directory domain named adatum.com. Client computers are deployed by usingWindows Deployment Services (WDS).

From Active Directory Users and Computers on a domain controller named DO, you attempt to create a newcomputer account as shown in the exhibit. (Click the Exhibit button.)

You need to ensure that you configure computer accounts as managed accounts when you create thecomputer accounts from Active Directory Users and Computers.

What should you do on DC1?

Exhibit:

Page 42: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Install the User Interfaces and Infrastructure feature.B. From the View menu in Active Directory Users and Computers, select Users, Contacts, Groups, and

Computers as containers.C. Install the Windows Deployment Services Tools role administration tool.D. From the View menu in Active Directory Users and Computers, select Advanced Features.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:http://technet.microsoft.com/en-us/library/cc754469.aspx

QUESTION 56You have a server named Server1 that runs Windows Server 2012. On Server1, you configure a custom DataCollector Set (DCS) named DCS1.You need to ensure that all performance log data that is older than 30 days is deleted automatically.

What should you configure?

A. a File Server Resource Manager (FSRM) quota on the %Systemdrive%\PerfLogs folderB. a schedule for DCS1C. the Data Manager settings of DCS1D. a File Server Resource Manager (FSRM) file screen on the %Systemdrive%\PerfLogs folder

Correct Answer: CSection: (none)

Page 43: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:

QUESTION 57You have a server named Server1 that runs Windows Server 2012. You create a custom Data Collector Set(DCS) named DCS1.You need to configure DCS1 to meet the following requirements:· Automatically run a program when the amount of total free disk space on Server1 drops below 10 percent ofcapacity.· Log the current values of several registry settings.

Which two should you configure in DCS1? (Each correct answer presents part of the solution. Choose two.)

A. System configuration informationB. A performance counterC. Event trace dataD. A Performance Counter Alert

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc766404.aspx

· Automatically run a program when the amount of total free disk space on Server1 drops below 10 percent ofcapacity.- You can also configure alerts to start applications and performance logs· Log the current values of several registry settings.System configuration information allows you to record the state of, and changes to, registry keys.

QUESTION 58Your network contains an Active Directory domain named contoso.com. All client computers connect to theInternet by using a server that has Microsoft Forefront Threat Management Gateway (TMG) installed. You deploy a server named Server1 thatruns Windows Server 2012. You install the Windows Server Update Services server role on Server1. From the Windows Server UpdateServices Configuration Wizard, you click Start Connecting and you receive an HTTP error message.You need to configure Server1 to download Windows updates from the Internet.

What should you do?

A. From the Update Services console, modify the Synchronization Schedule options.B. From Windows Internet Explorer, modify the Connections settings.C. From Windows Internet Explorer, modify the Security settings.D. From the Update Services console, modify the Update Source and Proxy Server options.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

Page 44: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 59You have a server named Server1 that runs Windows Server 2012. Server1 has the Windows Server UpdateServices server role installed.You need to configure Windows Server Update Services (WSUS) to support Secure Sockets Layer (SSL).

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A. Run the wsusutil.exe command.B. From Internet Information Services (IIS) Manager, modify the bindings of the WSUS website.C. From Internet Information Services (IIS) Manager, modify the connection strings of the WSUS website.D. Run the iisreset.exe command.E. Install a server certificate.

Correct Answer: ABESection: (none)Explanation

Explanation/Reference:http://www.vkernel.ro/blog/configure-wsus-to-use-ssl

1- first we need to request a certificate for the WSUS web site, so open IIS, click the server name, then openServer Certificates.On the Actions pane click Create Domain Certificate.

2- To add the signing certificate to the WSUS Web site in IIS 7.0On the WSUS server, open Internet Information Services (IIS) Manager.Expand Sites, right-click the WSUS Web site, and then click Edit Bindings.In the Site Binding dialog box, select the https binding, and click Edit to open the Edit Site Binding dialog box.Select the appropriate Web server certificate in the SSL certificate box, and then click OK.Click Close to exit the Site Bindings dialog box, and then click OK to close Internet Information Services (IIS)Manager.

3- WSUSUtil.exe configuressl <FQDN of the software update point site system> (the name in your certificate)

WSUSUtil.exe configuressl <Intranet FQDN of the software update point site system>.

4- The next step is to point your clients to the correct url, by modifying the existing GPO or creating a new one.Open the policy Specify intranet Microsoft update service location and type the new url in the form https://YourWSUSserver.The gpupdate /force command will just download all the GPO’s and re-apply them to the client, it won’t forcethe client to check for updates. For that you need to use wuauclt /detectnow.

http://technet.microsoft.com/en-us/library/bb680861.aspx

QUESTION 60Your network contains a domain controller named DC1 that runs Windows Server 2012. You create a customData Collector Set (DCS) named DCS1.You need to configure DCS1 to collect the following information:· The amount of Active Directory data replicated between DC1 and the other domain controllers· The current values of several registry settings

Which two should you configure in DCS1? (Each correct answer presents part of the solution. Choose two.)

A. Event trace dataB. System configuration informationC. A Performance Counter AlertD. A Performance Counter

Page 45: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer: BDSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc766404.aspx

QUESTION 61You have a VHD that contains an image of Windows Server 2012.You need to apply an update package to the image.

Which DISM option should you use?

A. /Add-ProvisionedAppxPackageB. /Cleanup-ImageC. /Add-PackageD. /Apply-Unattend

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Apply the update package (.msu) file by typing the following at a command prompt, replacing <file_path> withthe full path to the configuration set:

DISM /image:C:\MyDir\Mount /Add-Package /Packagepath:<file_path>

http://msdn.microsoft.com/en-us/library/ff794819.aspx

QUESTION 62Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012 and a server named Server2 that has the File Services server role installed. You install the WindowsDeployment Services server role on Server1. You plan to use Server2 as a reference computer.You need to create an image of Server2 by using Windows Deployment Services.

Which type of image should you add to Server1 first?

A. BootB. DiscoveryC. InstallD. Capture

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd637996(v=ws.10).aspx

QUESTION 63You have a server named Server1 that runs Windows Server 2012. Server1 has the Windows Server UpdateServices roll installed.Server1 stores update files locally in C:\Updates.

Page 46: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

You need to change the location in which the updates files are stored to D:\Updates

What should you do?

A. From the Update Services Console, run the Windows Server Update Services Configuration WizardB. From the command prompt, run wsusutil.exe and specify the movecontent parameterC. From the command prompt, run wsusutil.exe and specify the export parameterD. From the Update Services Console, configure the update Files and Languages option

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc720466(v=ws.10).aspx

QUESTION 64You have Site1 with 400 desktops and Site2 with 150 desktops. You have a WSUS Server to deploy updatesfor both sites.

You need to make sure that all computers in the same site will have the same updates.

What should you configure?

A. Computer GroupsB. Security GroupsC. Synchronization OptionsD. Classifications

Correct Answer: ASection: (none)Explanation

Explanation/Reference:A. WSUS allows you to target updates to groups of client computers, so you can ensure that specific computersalways get the right updates at the most convenient times. For example, if all the computers in one department(such as the Accounting team) have a specific configuration, you can set up a group for that team, decidewhich updates their computers need and what time they should be installed, and then use WSUS reports toevaluate the updates for the team.

http://technet.microsoft.com/en-us/library/hh328559(v=ws.10).aspx

QUESTION 65You have a WDS server named Server1 on Windows Server 2012.

You need to automate the WDS deployment.

Which Tab should you configure?

A. Boot PropertiesB. Client PropertiesC. Network Settings D. PXE Response Settings

Correct Answer: BSection: (none)

Page 47: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:B. On the Client tab, select Enable unattended installation, browse to the appropriate unattend file, and thenclick Open.http://technet.microsoft.com/en-us/library/dd637990(v=ws.10).aspx

QUESTION 66WDS. how to import GUID and MAC address?

A. /get-AutoAddDevicesB. /get-DeviceC. /addD. /enable

Correct Answer: BSection: (none)Explanation

Explanation/Reference:wdsutil /get-device /id:01-23-45-67-89-ABwdsutil /get-device /id:0123456789AB

QUESTION 67about not support PXE, you should first add mirrors

Page 48: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. bootB. installC. discoveryD. capture

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd637996(v=ws.10).aspx

WDSUTIL /New-DiscoverImage /Image:<name> /Architecture:{x86|x64|ia64} /DestinationImage /FilePath:<path and name to new file>. To specify whichserver the discover image connects to, append /WDSServer:<server name orIP>.

QUESTION 68You are a admin (what a suprise huh?) you have wsus with 2 sites wich contain computers.you want to have the ability to update the computers per site or together.wich 3 steps do you do?

A. Create computer groups in wsusB. Create synchronization optionsC. Create GPO and configure updatesD. Under Tasks , click Synchronize now

Correct Answer: ABCSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/hh852346.aspx

http://technet.microsoft.com/es-es/library/cc708455(v=ws.10).aspx

Page 49: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 69Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012 and a server named Server2 that has the File Services server roleinstalled.

You install the Windows Deployment Services server role on Server1.

You plan to use Server2 as a reference computer.

You need to create an image of Server2 by using Windows Deployment Services.

Which type of image should you add to Server1 first?

A. InstallB. BootC. DiscoveryD. Capture

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 70You have a server named Server1 that runs Windows Server 2012. You create a Data Collector Set (DCS)named DCS1.

You need to configure DCS1 to log data to D:\logs.

What should you do?

A. Right-click DCS1 and click Properties.B. Right-click DCS1 and click Save template...C. Right-click DCS1 and click Data Manager...D. Right-click DCS1 and click Export list...

Correct Answer: ASection: (none)Explanation

Explanation/Reference:Explanation: ?

QUESTION 71You have a server named WSUS1 that runs Windows Server 2012. WSUS1 has the Windows Server UpdateServices server role installed and has one volume.

You add a new hard disk to WSUS1 and then create a volume on the hard disk.

You need to ensure that the Windows Server Update Services (WSUS) update files are stored on the newvolume.

What should you do?

Page 50: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. From a command prompt, run wsusutil.exe and specify the movecontent parameter.B. From the Update Services console, run the Windows Server Update Services Configuration Wizard.C. From the Update Services console, configure the Update Files and Languages option.D. From a command prompt, run wsusutil.exe and specify the export parameter.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation:?

QUESTION 72Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8Pro. You have a Group Policy object (GPO) named GP1. GP1 is linked to the domain. GP1 contains the Windows Internet Explorer 10 and 11 Internet Settings. The settings are shown in the exhibit. (Click the Exhibit button.)Users report that when they open Windows Internet Explorer, the home page is NOT set to http://www.contoso.com.You need to ensure that the home page is set to http://www.contoso.com the next time users log on to thedomain.

What should you do?

Exhibit:

Page 51: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. On each client computer, run gpupdate.exe.B. Open the Internet Explorer 10 and 11 Internet Settings, and then press F5.C. Open the Internet Explorer 10 and 11 Internet Settings, and then modify the Tabs settings.D. On each client computer, run Invoke-GPupdate.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:it could be A ?

http://technet.microsoft.com/en-us/library/hh967455.aspx

The dotted red underline in the exhibit means that the setting is disabled.Pressing F5 will enable all items in tabPressing F6 will enable just a single selected itemPressing F7 will disable a single selected itemPressing F8 will disable all items in tab (already in this mode.)

QUESTION 73Your network contains an Active Directory domain named contoso.com. The domain does not contain acertification authority (CA).

Page 52: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

All servers run Windows Server 2012. All client computers run Windows 8.You need to add a data recovery agent for the Encrypting File System (EFS) to the domain.

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two).

A. From the Default Domain Controllers policy, select Create Data Recovery Agent.B. From the Default Domain Controllers policy, select Add Data Recovery Agent. C. From Windows PowerShell, run Get-Certificate.D. From the Default Domain Policy, select Add Data Recovery Agent.E. From a command prompt, run cipher.exe.F. From the Default Domain Policy, select Create Data Recovery Agent.

Correct Answer: CDSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc778448(v=ws.10).aspx

QUESTION 74Your network contains multiple Active Directory sites.You have a Distributed File System (DFS) namespace that has a folder target in each site.You discover that some client computers connect to DFS targets in other sites.You need to ensure that the client computers only connect to a DFS target in their respective site.

What should you modify?

A. the properties of the Active Directory site links.B. the properties of the Active Directory sites.C. the delegation settings of the namespaceD. the referral settings of the namespace

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 75Your network contains an Active Directory domain named contoso.com. The domain functional level inWindows Server 2008. All domain controllers run Windows Server 2008 R2.The domain contains a file server named Server1 that runs Windows Server 2012.Server1 has a BitLocker Drive Encryption (BitLocker)-encrypted drive. Server1 uses a trusted Platform Module(TPM) chip.You enable the Turn on TPM backup to Active Directory Domain Services policy setting by using a Group Policyobject (GPO).You need to ensure that you can back up the BitLocker recovery information to Active Directory.

What should you do?

A. Upgrade a domain controller to Windows 2012.B. Enable the Store BitLocker recovery information in the Active Directory Services (Windows Server2008 and

Windows Vista) policy settings.C. Raise the forest functional level to Windows 2008 R2.D. Add a BitLocker data recovery agent

Page 53: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd875529(v=ws.10).aspx

QUESTION 76Your company has a main office and a branch office. The main office is located in Seattle. The branch office islocated in Montreal. Each office is configured as an Active Directory site. The network contains an Active Directory domain namedadatum.com. The Seattle office contains a file server named Server1. The Montreal office contains a file server namedServer2. The servers run Windows Server 2012 and have the File and Storage Services server role, the DFSNamespaces role service, and the DFS Replication role service installed. Server1 and Server2 each have a share named Share1 that is replicated by using DFS Replication. You need to ensure that users connect to the replicated folder in their respective office when they connect to \\contoso.com\Share1.

Which three actions should you perform? (Each correct answer presents part of the solution. Choose three.)

A. Share and publish the replicated folder.B. Modify the Referrals settings.C. Create a new topology.D. Create a namespace.E. Create a replication connection.

Correct Answer: ABDSection: (none)Explanation

Explanation/Reference:To create a namespace Click Start, point to Administrative Tools , and then click DFS Management .

In the console tree, right-click the Namespaces node, and then click New Namespace .

Follow the instructions in the New Namespace Wizard .

To create a stand-alone namespace on a failover cluster, specify the name of a clustered file server instanceon the Namespace Server page of the New Namespace Wizard . Important Do not attempt to create a domain-based namespace using the Windows Server 2008 mode unless theforest functional level is Windows Server 2003 or higher. Doing so can result in a namespace for which youcannot delete DFS folders, yielding the following error message: “The folder cannot be deleted. Cannotcomplete this function.”http://technet.microsoft.com/en-us/library/cc731531.aspx

To share a replicated folder and publish it to a DF S namespace

1. Click Start, point to Administrative Tools, and then click DFS Management.

2. In the console tree, under the Replication node, click the replication group that contains the replicatedfolder you want to share.

Page 54: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

3. In the details pane, on the Replicated Folders tab, right-click the replicated folder that you want to share,and then click Share and Publish in Namespace .

4. In the Share and Publish Replicated Folder Wizard, click Share and publish the replicated folder in anamespace , and then follow the steps in the wizard.http://technet.microsoft.com/en-us/library/cc772379.aspx

http://technet.microsoft.com/en-us/library/cc732863%28v=ws.10%29.aspx

QUESTION 77You have a server named Server1 that runs Windows Server 2012. An administrator creates a quota as shownin the Quota exhibit. (Click the Exhibit button.)You run the dir command as shown in the Dir exhibit. (Click the Exhibit button.)

You need to ensure that D:\Folder1 can only consume 100 MB of disk space. What should you do?

Quota (exhibit):

Dir (exhibit):

A. From File Server Resource Manager, edit the existing quota.B. From the properties of drive D, enable quota management.C. From the Services console, set the Startup Type of the Optimize drives service to Automatic.D. From File Server Resource Manager, create a new quota.

Page 55: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

Page 56: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Mix-QB

QUESTION 1Your network contains an Active Directory forest. The forest contains two domains named contoso.com andfabrikam.com. All of the DNS servers in both of the domains run Windows Server 2012. The network contains two serversnamed Server1 and Server2. Server1 hosts an Active Directory-integrated zone for contoso.com. Server2 hosts an Active Directory-integrated zone for fabrikam.com. Server1 and Server2 connect to each other by using a WAN link. Client computers that connect to Server1 for name resolution cannot resolve names in fabrikam.com.You need to configure Server1 to support the resolution of names in fabrikam.com.The solution must ensure that users in contoso.com can resolve names in fabrikam.com if the WAN link fails.

What should you do on Server1?

A. Add a forwarder.B. Create a conditional forwarder.C. Create a secondary zone.D. Create a stub zone.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 2Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs). Currently, there are no enforced GPOs. You need to prevent all of the GPOs at the site level and at the domainlevel from being applied to users and computersin an organizational unit (OU) named OU1.You want to achieve this goal by using the minimum amount of Administrative effort.

What should you use?

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Import-GPOH. Restore-GPOI. Set-GPInheritanceJ. Set-GPLinkK. Set-GPPermissionL. GpupdateM. Add-ADGroupMember

Correct Answer: ISection: (none)Explanation

Page 57: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:http://technet.microsoft.com/en-us/library/ee461032.aspx

http://technet.microsoft.com/en-us/library/cc757050.aspx

QUESTION 3Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs). Currently, there are no enforced GPOs. You have two GPOs linked to an organizational unit (OU) named OU1.You need to change the precedence order of the GPOs.

What should you use?

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Restore-GPOH. Set-GPInheritanceI. Set-GPLinkJ. Set-GPPermissionK. GpupdateL. Add-ADGroupMember

Correct Answer: ISection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/ee461022.aspx

The Set-GPLink cmdlet sets the properties of a GPO link.

You can set the following properties:-- Enabled. If the GPO link is enabled, the settings of the GPO are applied when Group Policy is processed forthe site, domain or OU.-- Enforced. If the GPO link is enforced, it cannot be blocked at a lower-level (in the Group Policy processinghierarchy) container.-- Order. The order specifies the precedence that the settings of the GPO take over conflicting settings in otherGPOs that are linked (and enabled) to the same site, domain, or OU.

QUESTION 4Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8Pro. You have a Group Policy object (GPO) named GP1. GP1 is linked to the domain. GP1 contains the Windows Internet Explorer 10 and 11 Internet Settings. The settings are shown in the exhibit. (Click the Exhibit button.)Users report that when they open Windows Internet Explorer, the home page is NOT set to http://www.contoso.com.You need to ensure that the home page is set to http://www.contoso.com the next time users log on to thedomain.

What should you do?

Exhibit:

Page 58: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. On each client computer, run gpupdate.exe.B. Open the Internet Explorer 10 and 11 Internet Settings, and then press F5.C. Open the Internet Explorer 10 and 11 Internet Settings, and then modify the Tabs settings.D. On each client computer, run Invoke-GPupdate.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/hh967455.aspx

QUESTION 5Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. You have a Group Policy object (GPO) named GPO1 that contains hundreds of settings. GPO1 is linked to anorganizational unit (OU) named OU1. OU1 contains 200 client computers. You plan to unlink GPO1 from OU1. You need to identify which GPO settings will be removed from the computers after GPO1 is unlinked fromOU1.

Which two GPO settings should you identify? (Each correct answer presents part of the solution. Choose two.)

A. The managed Administrative Template settings

Page 59: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

B. The unmanaged Administrative Template settingsC. The System Services security settingsD. The Event Log security settingsE. The Restricted Groups security settings

Correct Answer: ADSection: (none)Explanation

Explanation/Reference:Hay dos tipos de configuraciones de directiva de las plantillas administrativas: Administrada y Noadministrada. El servicio de directiva de grupo controla la configuración de directiva Administrada y quita unaconfiguración de directiva cuando ya no esté dentro del ámbito del usuario o el equipo.

El servicio de directiva de grupo no controla la co nfiguración de directiva no administrada . Estasconfiguraciones de directiva son persistentes . El servicio de directiva de grupo no quita una configuración dedirectiva no administrada, ni siquiera si no está dentro del ámbito del usuario o el equipo. Normalmente, estostipos de configuraciones de directiva se usan para establecer preferencias para los componentes del sistemaoperativo no habilitados para la directiva. También puede usar la configuración de directiva no administradapara la configuración de aplicaciones.

QUESTION 6Your network contains an Active Directory domain named contoso.com. The domain contains an organizationalunit (OU) named IT and a OU named Sales. All of the help desk user accounts are located in the IT OU. All of the sales user accounts are located in theSales OU. The Sales OU contains a global security group named G_Sales. The IT OU contains a global security groupnamed G_HelpDesk.You need to ensure that members of G_HelpDesk can perform the following tasks:· Reset the passwords of the sales users.· Force the sales users to change their password at their next logon.

What should you do?

A. Run the Set-ADFinecrainedPasswordPolicy cmdlet and specify the -identity parameter.B. Right-click the IT OU and select Delegate Control.C. Right-click the Sales OU and select Delegate Control.D. Run the Set-ADAccountPassword cmdlet and specify the -identity parameter.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 7how to give the minimum required permission to a user who wants to promote a RODC.

A. member of the Domain Admins group B. allowed to attach the server to the RODC computer accountC. Local adminD. organization admin

Page 60: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer: BCSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/jj574152.aspx

The Delegation of RODC Installation and Administration dialog enables you to configure a user or groupcontaining users who are allowed to attach the server to the RODC computer account. The user or group specified in this dialog gains local administrative permissions to the RODC. The specifieduser or members of the specified group can perform operations on the RODC with privileges equivalent to thecomputer’s Administrators group. They are not members of the Domain Admins or domain built-inAdministrators groups.

http://technet.microsoft.com/es-es/library/cc770627(v=ws.10).aspx

Durante la primera fase, el asistente registra todos los datos acerca del RODC que se almacenarán en la basede datos de Active Directory, como su nombre de cuenta de controlador de dominio y el sitio en el que seubicará. Esta fase debe realizarla un miembro del grupo Administradores del dominio. El administrador que crea la cuenta de RODC también puede especificar en ese momento qué usuarios ogrupos pueden completar la siguiente fase de la instalación.

...En la página Delegación de instalación y administración de RODC , escriba el nombre del usuario o grupoque asociará el servidor a la cuenta de RODC que va a crear. Sólo puede escribir el nombre de una entidad deseguridad. Para buscar en el directorio un usuario o grupo específico, haga clic en Establecer . En Seleccione usuarios,equipos o grupos , escriba el nombre del usuario o del grupo. Se recomienda delegar la instalación yadministración del RODC en un grupo. Este usuario o grupo tendrá también derechos administrativos en el RODC después de la instalación. Si no seespecifica un usuario o un grupo, únicamente podrá asociar el servidor a la cuenta un miembro del grupoAdminis. del dominio o Administradores de empresas.Cuando termine, haga clic en Siguiente ....

Page 61: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

La siguiente fase de la instalación la puede realizar en la sucursal cualquier usuario o grupo en quien se hayadelegado el derecho de completar la instalación cuando se creó la cuenta. Esta fase no requiere la pertenenciaa grupos integrados, como el grupo Administradores del dominio. Si el usuario que crea la cuenta de RODC noespecifica ningún delegado para completar la instalación (y administrar el RODC), únicamente un miembro delos grupos Administradores del dominio o Administradores de organización podrá completarla.

QUESTION 8Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. A domain controller named DC1 has the ADMX Migrator tool installed. You have a custom AdministrativeTemplate file on DC1 named Template1.adm. You need to add a custom registry entry to Template1.adm by using the ADMX Migrator tool.

Which action should you run first?

A. New CategoryB. Load TemplateC. New Policy SettingD. Generate ADMX from ADM

Correct Answer: DSection: (none)Explanation

Page 62: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:

QUESTION 9Your network contains an Active Directory domain named adatum.com.You need to audit changes to the files in the SYSVOL shares on all of the domain controllers.The solution must minimize the amount of SYSVOL replication traffic caused by the audit.

Which two settings should you configure? (Each correct answer presents part of the solution. Choose two.)

A. Audit Policy\Audit system eventsB. Advanced Audit Policy Configuration\DS AccessC. Advanced Audit Policy Configuration\Global Object Access AuditingD. Audit Policy\Audit object accessE. Audit Policy\Audit directory service accessF. Advanced Audit Policy Configuration\Object Access

Correct Answer: DFSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd772690(v=ws.10).aspx

There are no system access control lists (SACLs) for shares; therefore, once this setting is enabled, access toall shares on the system will be audited.

The answer to that question should be

Audit Policy\Audit object access Advanced Audit Policy Configuration\Object Access

In that there is a security setting "Access File Share" and "Access Detailed file share".

QUESTION 10Your network contains an Active Directory domain named contoso.com. You deploy a web-based applicationnamed App1 to a server named Server1. App1 uses an application pool named AppPool1. AppPool1 uses a domain user account named User1 as itsidentity. You need to configure Kerberos constrained delegation for User1.

Which three actions should you perform? To answer, move the three appropriate actions from the list of actionsto the answer area and arrange them in the correct order

Select and Place:

Page 63: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Page 64: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:first answer should be "setspn -L" - to check for SPNs of User1. After that we should add HTTP SPN for User1"setspn -s" so delegation tab appears and we can select "Trust this user for delegation to specified servicesonly"

QUESTION 11Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. The domain contains 500 client computers that run Windows 8 Enterprise.

You implement a Group Policy central store.

You have an application named Appl. Appl requires that a custom registry setting be deployed to all of thecomputers.

You need to deploy the custom registry setting. The solution must minimize administrator effort.

What should you configure in a Group Policy object (GPO)?

A. The Administrative TemplatesB. An application control policyC. The Group Policy preferencesD. Software installation setting

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:A.

User Configuration\Software Settings is for software settings that apply to users regardless of which computerthey log on to. This folder also contains the Software installation subitem, and it might contain other subitemsthat are placed there by independent software vendors.B.Las políticas de control de aplicación especifican qué programas se pueden ejecutar en el equipo local ycuáles no . Computer Configuration\Windows Settings\Security Settings\Application Control Policies http://technet.microsoft.com/es-es/library/hh125923%28v=WS.10%29.aspx

C.Group Policy preferences provide the means to simplify deployment and standardize configurations. They addto Group Policy a centralized system for deploying preferences (that is, settings that users can change later).You can also use Group Policy preferences to configure applications that are not Group Policy-aware. By usingGroup Policy preferences, you can change or delete almost any registry settin g, file or folder, shortcut,and more . You are not limited by the contents of Administrative Template files. The Group Policy ManagementEditor (GPME) includes Group Policy preferences.http://technet.microsoft.com/en-us/library/gg699429.aspxhttp://www.unidesk.com/blog/gpos-set-custom-registry-entries-virtual-desktops-disabling-machine-password

D.

Computer Configuration\Software Settings is for software settings that apply to all users who log on to thecomputer. This folder contains the Software installation subitem, and it might contain other subitems that areplaced there by independent software vendors.http://technet.microsoft.com/en-us/library/cc784044%28v=ws.10%29.aspx

QUESTION 12

Page 65: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that runs Windows Server 2012.

You create an Active Directory snapshot of DC1 each day.

You need to view the contents of an Active Directory snapshot from two days ago.

What should you do first?

A. Run the dsamain.exe command.B. Stop the Active Directory Domain Services (AD DS) service.C. Run the ntdsutil.exe command.D. Start the Volume Shadow Copy Service (VSS).

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:

Mounting an Active Directory snapshot

Before connecting to the snapshot we need to mount it. By looking at the results of the List All command in step#8 above, identify the snapshot that you wish to mount, and note the number next to it.In order to mount an Active Directory snapshot follow these steps: Log on as a member of the Domain Admins group to one of your Windows Server 2008 Domain Controllers. Open a Command Prompt window by clicking on the CMD shortcut in the Start menu, or by typing CMD andpressing Enter in the Run or Quick Search parts of the Start menu.

Note: You must run NTDSUTIL from an elevated command prompt. To open an elevated command prompt,click Start, right-click Command Prompt, and then click Run as administrator. In the CMD window, type the following command: ntdsutil

In the CMD window, type the following command: snapshot

To view all available snapshots, in the CMD window, type the following command: list all

The result should look like this: snapshot: List All 1: 2008/10/25:03:14 {ec53ad62-8312-426f-8ad4-d 47768351c9a} 2: C: {15c6f880-cc5c-483b-86cf-8dc2d3449348}

In this example we only have one snapshot available, one from 2008/10/25 at 03:14AM (yes, I write articlesat this time…). We'll mount this one.

In the CMD window, type the following command: mount 2

The result should look like this: snapshot: mount 2 Snapshot {15c6f880-cc5c-483b-86cf-8dc2d3449348} mounted asC:'$SNAP_200810250314_VOLUMEC$'

Next, you can leave the NTDSUTIL running, or you can quit by typing quit 2 times.

Page 66: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Note: Like the above command, the mounting process can also be run in one line. However, note that NTDSUTIL requires that the "list all" command be ru n in the same session that you mount thesnapshot . So in order to mount the snapshot with a one-liner, you will need to run "list all" first.

ntdsutil snapshot "list all" "mount 2" quit quit

Note: You do not need to quit from the NTDSUTIL command, you can keep it open assuming that you'llprobably want to unmount the snapshot right after working with it.

QUESTION 13Your network contains an Active Directory domain named adatum.com. All domain controllers run WindowsServer 2012. The domain contains a virtual machine named DC2.

On DC2, you run Get-ADDCCloningExcludedApplicationList and receive the output shown in the following table.

You need to ensure that you can clone DC2.

Which two actions should you perform? (Each correct answer presents part of the solution.Choose two.)

A. Create an empty file named CustomDCClonesAllowList.xmlB. Add the following information to the DCCloneConfigSchema.xsd

<AllowList> <Allow> <Name>App1</Name> <Type>Service</Type> </Allow></AllowList>

C. Create a filename DCCloneConfig.xml that contains the following information<AllowList> <Allow> <Name>App1</Name> <Type>Service</Type> </Allow></AllowList>

D. Create a filename CustomDCCloneAllowList.xml that contains the following information<AllowList> <Allow> <Name>App1</Name> <Type>Service</Type> </Allow></AllowList>

E. Create an empty file named DCCloneConfig.xml

Correct Answer: DESection: (none)Explanation

Explanation/Reference:

Page 67: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation:

D: Run Get-ADDCCloningExcludedApplicationList cmdlet In this procedure, run the Get-ADDCCloningExcludedApplicationList cmdlet on the source virtualized domain controller to identify anyprograms or services that are not evaluated for cloning. You need to run the Get-ADDCCloningExcludedApplicationList cmdlet before the New- ADDCCloneConfigFile cmdlet because if theNew-ADDCCloneConfigFile cmdlet detects an excluded application, it will not create a DCCloneConfig.xml file.To identify applications or services that run on a source domain controller which have not been evaluated forcloningGet-ADDCCloningExcludedApplicationListGet-ADDCCloningExcludedApplicationList -GenerateXml

E: The clone domain controller will be located in the same site as the source domain controller unless adifferent site is specified in the DCCloneConfig.xml file.

Note:* The Get-ADDCCloningExcludedApplicationList cmdlet searches the local domain controller for programs andservices in the installed programs database, the services control manager that are not specified in the defaultand user defined inclusion list. The applications in the resulting list can be added to the user defined exclusionlist if they are determined to support cloning. If the applications are not cloneable, they should be removed fromthe source domain controller before the clone media is created. Any application that appears in cmdlet outputand is not included in the user defined inclusion list will force cloning to fail.* The Get-ADDCCloningExcludedApplicationList cmdlet needs to be run before the New-ADDCCloneConfigFile cmdlet is used because if the New-ADDCCloneConfigFile cmdlet detects an excludedapplication, it will not create a DCCloneConfig.xml file.* DCCloneConfig.xml is an XML configuration file that contains all of the settings the cloned DC will take when itboots. This includes network settings, DNS, WINS, AD site name, new DC name and more. This file can begenerated in a few different ways.

The New-ADDCCloneConfig cmdlet in PowerShellBy hand with an XML editorBy editing an existing config file, again with an XML editor (Notepad is not an XML editor.)

Reference: Introduction to Active Directory Domain Services (AD DS) Virtualization (Level 100)

Seehttp://blogs.dirteam.com/blogs/sanderberkouwer/archive/2012/09/10/new-features-in-active-directory-domain-services-in-windows-server-2012-part-13-domain-controller-cloning.aspx

QUESTION 14Your network contains an Active Directory domain named contoso.com. The domain contains a member servernamed Server1.Server1 has the Web Server (IIS) server role installed. On Server1, you install a managed service accountnamed Service1. You attempt to configure the World Wide Web Publishing Service as shown in the exhibit. (Click the Exhibitbutton.)You receive the following error message: "The account name is invalid or does not exist, or the password isinvalid for the account name specified."You need to ensure that the World Wide Web Publishing Service can log on by using the managed serviceaccount.

What should you do?

Exhibit:

Page 68: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Specify contoso\service1$ as the account name.B. Specify [email protected] as the account name.C. Reset the password for the account.D. Enter and confirm the password for the account.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://blogs.technet.com/b/askds/archive/2009/09/10/managed-service-accounts-understanding-implementing-best-practices-and-troubleshooting.aspx

QUESTION 15Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. You pre-create a read-only domain controller (P.QDC) account named RODC1. You export the settings of RODC1 to a file named File1.txt. You need to promote RODC1 by using File1.txt.

Which tool should you use?

A. The Dcpromo commandB. The Install-WindowsFeature cmdletC. The Install-ADDSDomainController cmdletD. The Add-WindowsFeature cmdletE. The Dism command

Correct Answer: A

Page 69: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/jj574152.aspx

"If you have experience creating read-only domain controllers, you will discover that the installation wizard hasthe same graphical interface as seen when using the older Active Directory Users and Computers snap-in fromWindows Server 2008 and uses the same code, which includes exporting the configuration in the unattend fileformat used by the obsolete dcpromo."

"The Summary dialog enables you to confirm your settings. This is the last opportunity to stop the installationbefore the wizard creates the staged account. Click Next when you are ready to create the staged RODCcomputer account. Click Export Settings to save an answer file in the obsolete dcpromo unattend file format."

QUESTION 16Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2008 R2. The domain contains three servers that run Windows Server 2012. The servers are configured as shown in the following table.

Server1 and Server2 are configured in a Network Load Balancing (NLB) cluster. The NLB cluster hosts awebsite named Web1 that uses an application pool named App1. Web1 uses a database named DB1 as its data store. You create an account named User1. You configureUser1, as the identity of App1.You need to ensure that contoso.com domain users accessing Web1 connect to DB1 by using their owncredentials.

Which two actions should you perform? (Each correct answer presents part of the solution. Choose two.)

A. Configure the delegation settings of Server3.B. Create a Service Principal Name (SPN) for User1.C. Configure the delegation settings of User1.D. Create a matching Service Principal Name (SPN) for Server1 and Server2.E. Configure the delegation settings of Server1 and Server2.

Correct Answer: BCSection: (none)Explanation

Explanation/Reference:To create a service principal nameOpen an elevated command prompt. Click Start , and in the search window, type Command Prompt .Right-click Command Prompt , and then click Run as administrator .At the command prompt, create the SPN. The syntax is:

setspn -S InstanceName/FullyQualifiedDomainNameOfSe rver:Port Domain \User

If your version of setspn.exe does not recognize -S, retry the command using -A. See Walkthrough: Installing

Page 70: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

the Three Tiers on Three Computers for an example of how to create SPNs when deploying MicrosoftDynamics NAV.Delegating Access to the SQL Server ServiceConfiguring delegation means explicitly configuring the Microsoft Dynamics NAV Server service to delegate itsaccess to the database server on behalf of the RoleTailored client. To make the access more secure, youspecify delegation to a specific service on a specific server.To delegate access to the SQL Server serviceOn any server computer in the domain, click Start , and then click Run .In the Open field, type dsa.msc .This opens the Active Directory Users and Computers utility.To configure delegation, the functional level for the domain must be Windows Server 2003 or higher. To verifythe domain functional level, right-click the node for the domain where you have installed Microsoft DynamicsNAV, and then click Raise Domain Functional Level . If the level is not at least Windows Server 2003, thenraise it to that level.Right-click the node for the domain where you have installed Microsoft Dynamics NAV, and then click Find . In the Find Users, Contacts, and Group dialog box, type the name of the domain user in the Name field, andthen press ENTER.In the Search results area, right-click the domain user, and then click Properties .On the Delegation tab, click Trust this user for delegation to specified service s only , and then click UseKerberos only .Click Add to open the Add Services dialog box.In the Add Services window, click Users or Computers , and then type the name of the domain user. In the list of services for the domain user, click MSSQLSvc , which is the name of the SQL Server service.Click OK to exit the Add Services dialog box. Click OK to close all open dialog boxes.

http://msdn.microsoft.com/en-us/library/dd568720.aspx

Sobre identidades: http://www.iis.net/learn/manage/configuring-security/application-pool-identities

QUESTION 17Your network contains an Active Directory domain named contoso.com. Domain controllers run either WindowsServer 2003, Windows Server 2008 R2, or Windows Server 2012. A support technician accidentally deletes a user account named User1.You need to use tombstone reanimation to restore the User1 account.

Which tool should you use?

A. NtdsutilB. LdpC. EsentutlD. Active Directory Administrative Center

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/magazine/2007.09.tombstones.aspx

QUESTION 18Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC4 that runs Windows Server 2012. You create a DCCloneConfig.xml file.You need to clone DC4.

Where should you place DCCloneConfig.xml on DC4?

Page 71: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. %Systemroot%\SYSVOLB. %Programdata%\MicrosoftC. %Systemroot%\NTDSD. %Systemdrive%

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://blogs.technet.com/b/askpfeplat/archive/2012/10/01/virtual-domain-controller-cloning-in-windows-server-2012.aspx

As the output shows, the XML file is written to c:\windows\ntds. That's one of three valid locations where the filecan be placed for cloning. All three locations are:%windir%\NTDS Wherever the DIT lives (if you've changed the path to D:\NTDS, for example) The root of any removable media.

QUESTION 19Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1. You run ntdsutil {as shown in the exhibit}.You need to ensure that you can access the contents of the mounted snapshot.

What should you do?

Exhibit:

A. From a command prompt, run dsamain.exe -dbpath c:\$snap_201204131056_volumec$\windows\ntds\ntds.dit - Idapport 33389.

B. From a command prompt, run dsamain.exe -dbpath c:\$snap_201204131056_volumec$\windows\ntds

Page 72: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

\ntds.dit - Idapport 389.C. From the snapshot context of ntdsutil, run activate instance "NTDS".D. From the snapshot context of ntdsutil, run mount (79f94f82-5926-4f44-8af0-2f56d827a57d).

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 20Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1. On DC1, you add a new volume and you stop the Active Directory Domain Services (AD DS) service. You run ntdsutil.exe and you set NTDS as the active instance.You need to move the Active Directory database to the new volume.

Which Ntdsutil context should you use?

A. Configurable SettingsB. Partition managementC. IFMD. Files

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 21Your network contains an Active Directory domain named contoso.com. You create a user account namedUser1. The properties of User1 are shown in the exhibit. (Click the Exhibit button.)You plan to use the User1 account as a service account. The service will forward authentication requests toother servers.You need to ensure that you can view the Delegation tab from the properties of the User1 account.

What should you do first?

Exhibit:

Page 73: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Modify the Security settings of User1.B. Modify the user principal name (UPN) of User1.C. Configure a Service Principal Name (SPN) for User1.D. Configure the Name Mappings of User1.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://blogs.msdn.com/b/mattlind/archive/2010/01/14/delegation-tab-in-aduc-not-available-until-a-spn-is-set.aspx

QUESTION 22Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. On all of the domain controllers, Windows is installed in C:\Windows and the Active Directory database is located in D:\Windows\NTDS\. All of the domain controllers have a third-party application installed. The operating system fails to recognize that the application is compatible with domain controller cloning. You verify with the application vendor that the application supports domain controller cloning.You need to prepare a domain controller for cloning.

What should you do?

A. In D:\Windows\NTDS\, create an XML file named DCCloneConfig.xml and add the application information to

Page 74: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

the file.B. In D:\Windows\NTDS\, create an XML file named CustomDCCloneAllowList.xml and add the application

information to the file.C. In the root of a USB flash drive, add the application information to an XML file named

DefaultDCCloneAllowList.xml.D. In D:\Windows\NTDS, create an XML file named DefaultDCCloneAllowList.xml and add the application

information to the file.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://blogs.dirteam.com/blogs/sanderberkouwer/archive/2012/09/10/new-features-in-active-directory-domain-services-in-windows-server-2012-part-13-domain-controller-cloning.aspxhttp://www.thomasmaurer.ch/2012/08/windows-server-2012-hyper-v-how-to-clone-a-virtual-domain-controllerhttp://technet.microsoft.com/en-us/library/hh831734.aspxPlace the CustomDCCloneAllowList.xml file in the same folder as the Active Directory database (ntds.dit) onthe source Domain Controller.

QUESTION 23Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. On all of the domain controllers, Windows is installed in C:\Windows and the Active Directory database is located in D:\Windows\NTDS\. All of the domain controllers have a third-party application installed. The operating system fails to recognize that the application is compatible with domain controller cloning. You verify with the application vendor that the application supports domain controller cloning.You need to prepare a domain controller for cloning.

What should you do?

A. In the root of a USB flash drive, add the application information to an XML file namedDefaultDCCloneAllowList.xml.

B. In C:\Windows\system32\sysprep\actionfiles\, add the application information to an XML file namedSpecialize .xml.

C. In D:\Windows\NTDS\, create an XML file named CustomDCCloneAllowList.xml and add the applicationinformation to the file.

D. In C:\Windows\system32\sysprep\actionfiles\add the application information to an XML file namedRespecialize .xml.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 24Your network contains an Active Directory domain named adatum.com. The domain contains a domaincontroller named DC1. On DC1, you create a new volume named E. You restart DC1 in Directory Service Restore Mode. You open ntdsutil.exe and you set NTDS as the activeinstance.You need to move the Active Directory logs to E:\NTDS\.

Which Ntdsutil context should you use?

Page 75: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. IFMB. Configurable SettingsC. Partition managementD. Files

Correct Answer: DSection: (none)Explanation

Explanation/Reference:How to Move Log Files

Use the move logs to command to move the directory service log files to another folder. For the new settings totake effect, restart the computer after you move the log files.To move the log files, follow these steps:- Click Start, click Run, type ntdsutil in the Open box, and then press ENTER.- At the Ntdsutil command prompt, type files , and then press ENTER.- At the file maintenance command prompt, type move logs to new location (where new location is an existingfolder that you have created for this purpose), and then press ENTER.- Type quit , and then press ENTER.- Restart the computer.

http://support.microsoft.com/kb/816120#5

QUESTION 25Your network contains an Active Directory domain named contoso.com. The domain contains six domaincontrollers. The domain controllers are configured as shown in the following table.

The network contains a server named Server1 that has the Hyper-V server role installed. DC6 is a virtual machine that is hosted on Server1.You need to ensure that you can clone DC6.

Which FSMO role should you transfer to DC2?

A. Infrastructure MasterB. RID MasterC. Domain Naming MasterD. PDC emulator

Correct Answer: DSection: (none)

Page 76: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/hh831734.aspx#steps_deploy_vdc

QUESTION 26Your network contains an Active Directory domain named contoso.com. The domain contains a member servernamed Server1. Server1 runs Windows Server 2012 and has the Hyper-V server role installed.Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 and hosts aprocessor-intensive application names App1.Users report that App1 responds more slowly than expected.You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardwaresettings of VM1.

Which performance object should you monitor on Server1?

A. ProcessorB. Hyper-V Hypervisor Root Virtual ProcessorC. Hyper-V Hypervisor Logical ProcessorD. ProcessE. Hyper-V Hypervisor Virtual Processor

Correct Answer: ESection: (none)Explanation

Explanation/Reference:http://msdn.microsoft.com/en-us/library/cc768535(v=bts.10).aspx

QUESTION 27The contoso.com domain contains 2 domain controllers running Server 2012, AD recycle bin is enabled for thedomain. DC1 is configured to take AD snapshots daily, DC2 is set to take snapshots weekly.

Someone deletes a group containing 100 users, you need to recover this group,

What should you do?

A. Authoritative Restore B. Non Authoritative Restore C. Tombstone ReanimationD. Modify attribute isdeleted=true

Correct Answer: CSection: (none)Explanation

Explanation/Reference:C. Active Directory Recycle Bin, starting in Windows Server 2008 R2, builds on the existing tombstonereanimation infrastructure and enhances your ability to preserve and recover accidentally deleted ActiveDirectory objects.

http://technet.microsoft.com/en-us/library/hh831702.aspx

QUESTION 28You have a RODC named Server1 running Server 2012 .

Page 77: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

You need to add a RODC Administrator.

How do you complete the task?

A. dsmgmt.exeB. ntdsutilC. Add user to Local Administrator Group on Server1D. Use Security Group and modify RODC Delegated Administrator

Correct Answer: DSection: (none)Explanation

Explanation/Reference:D. Using ntdsutil or dsmgmt to specify the delegated RODC administrator account is not recommendedbecause the information is stored only locally on the RODC. You can only specify one security principal to bethe delegated RODC administrator. As a best practice, you should create a security group for each RODC andassign that group to be the delegated administrator. Then, you can add individual user accounts to the group,and each user can manage the RODC.

http://technet.microsoft.com/en-us/library/cc755310(v=ws.10).aspx

QUESTION 29Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. Alldomain controllers run Windows Server 2012.The domain contains two domain controllers. The domain controllers are configured as shown in the followingtable.

Active Directory Recycle Bin is enabled.You discover that a support technician accidentally removed 100 users from an Active Directory group namedGroup1 an hour ago.What should you do?

A. Perform a non-authoritative restore.B. Modify the is Recycled attribute of Group1.C. Perform an authoritative restore.D. Recover the items by using Active Directory Recycle Bin.

Correct Answer: DSection: (none)

Page 78: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:This is the only option that specifies "file" http://technet.microsoft.com/en-us/library/ff625687(v=ws.10).aspx)

QUESTION 30Your network contains an Active Directory domain named contoso.com. The domain contains a read-onlydomain controller (RODC) named RODC1.You create a global group named RODC_Admins.You need to provide the members of RODC_Admins with the ability to manage the hardware and the softwareon RODC1. The solution must not provide RODC_Admins with the ability to manage Active Directory objects.What should you do?

A. From Active Directory Users and Computers , configure the Managed By settings of the RODC1 account.B. From Active Directory Sites and Services, run the Delegation of Control WizardC. From Active Directory Users and Computers, run the Delegation of Control Wizard.D. From a command prompt, run the dsadd computer command.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc755310%28v=ws.10%29.aspx

QUESTION 31Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012.In a remote site, a support technician installs a server named DC10 that runs Windows Server 2012. DC10 iscurrently a member of a workgroup.You plan to promote DC10 to a read-only domain controller (RODC).You need to ensure that a user named Contoso/User1 can promote DC10 to a RODC in the contoso.comdomain. The solution must minimize the number of permissions assigned to User1.What should you do?

A. Join DC10 to the domain. Modify the properties of the DC10 computer accountB. From Active Directory Administrative Center, pre-create an RODC computer account.C. Join DC10 to the domain. Run dsmod and specify the /server switchD. From Active Directory Administrative Center, modify the security settings of the Domain Controllers

organizational unit (OU).

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 32Your network contains an Active Directory domain named contoso.com. The domain contains six domaincontrollers. The domain controllers are configured as shown in the following table.

Page 79: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

The network contains a server named Server1 that has the Hyper-V server role installed. DC6 is a virtualmachine that is hosted on Server1.

You need to ensure that you can clone DC6.

What should you do?

A. Transfer the schema master to DC6.B. Transfer the schema master to DC4.C. Transfer the PDC emulator to DC2.D. Transfer the PDC emulator to DC5.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 33Your network contains an Active Directory forest named contoso.com. All servers run Windows Server 2012.

You need to create a custom Active Directory application partition.

Which tool should you use?

A. DsaddB. DsmodC. NetdomD. Ntdsutil

Correct Answer: DSection: (none)Explanation

Explanation/Reference:Explanation: * To create or delete an application directory partition

* partition managementManages directory partitions for Active Directory Domain Services (AD DS) or Active Directory LightweightDirectory Services (AD LDS).

Page 80: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

This is a subcommand of Ntdsutil and Dsmgmt. Ntdsutil and Dsmgmt are command-line tools that are built intoWindows Server 2008 and Windows Server 2008 R2./ partition management create nc %s1 %s2Creates the application directory partition with distinguished name %s1, on the Active Directory domaincontroller or AD LDS instance with full DNS name %s2. If you specify "NULL" for %s2, this command uses thecurrently connected Active Directory domain controller. Use this command only with AD DS. For AD LDS, usecreate nc %s1 %s2 %s3.

Note:

* An application directory partition is a directory partition that is replicated only to specific domain controllers. Adomain controller that participates in the replication of a particular application directory partition hosts a replicaof that partition.

QUESTION 34Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. The domain contains two servers.

The servers are configured as shown in the following table.

Server1 and Server2 host a load-balanced website named Web1. Web1 runs by using an application poolnamed WebApp1. WebApp1 uses a group Managed Service Account named gMSA1 as its identity.

Domain users connect to Web1 by using either the name webl.contoso.com or the alias myweb.contoso.com.

You discover the following:

- When the users access Web1 by using webl.contoso.com, they authenticate by using Kerberos.- When the users access Web1 by using myweb.contoso.com, they authenticate by using NTLM.

You need to ensure that the users can authenticate by using Kerberos when they connect by usingmyweb.contoso.com.

What should you do?

A. Modify the properties of the WebApp1 application pool.B. Run the Add-ADComputerServiceAccount cmdlet.C. Modify the properties of the Web1 website.D. Modify the properties of the gMSA1 service account.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation: The Add-ADComputerServiceAccount cmdlet adds one or more computer service accounts to anActive Directory computer.

Page 81: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

The Computer parameter specifies the Active Directory computer that will host the new service accounts.Reference: Add-ADComputerServiceAccount

QUESTION 35Your network contains an Active Directory domain named contoso.com. The domain contains a member servernamed Server1. Server1 runs Windows Server 2012 and has the Hyper-V server role installed.

Server1 hosts 10 virtual machines. A virtual machine named VM1 runs Windows Server 2012 and hosts aprocessor-intensive application named Appl.

Users report that App1 responds more slowly than expected.

You need to monitor the processor usage on VM1 to identify whether changes must be made to the hardwaresettings of VM1.

Which performance object should you monitor on Server1?

A. ProcessorB. Hyper-V Hypervisor Virtual ProcessorC. Hyper-V Hypervisor Root Virtual ProcessorD. ProcessE. Hyper-V Hypervisor Logical Processor

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 36Your network contains an Active Directory domain named contoso.com. The domain contains six domaincontrollers named DC1, DC2, DC3, DC4, DC5, and DC6. Each domain controller has the DNS Server server role installed and hosts an Active Directory-integrated zonefor contoso.com. You plan to create a new Active Directory-integrated zone named litwareinc.com that will be used for testing. You need to ensure that the new zone will be available only on DC5 and DC6.

What should you do first?

A. Create an application directory partition.B. Change the zone replication scope.C. Create an Active Directory connection object.D. Create an Active Directory site link.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc754292.aspx

QUESTION 37Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012.

Page 82: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

You pre-create a read-only domain controller (P.QDC) account named RODC1.

You export the settings of RODC1 to a file named Filel.txt.

You need to promote RODC1 by using Filel.txt.Which tool should you use?

A. The Install-WindowsFeature cmdletB. The Add-WindowsFeature cmdletC. The Dism commandD. The Install-ADDSDomainController cmdletE. the Dcpromo command

Correct Answer: ESection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 38How to configure IIS to change the authentication (kerberos or ntlm)

A. cscript adsutil.vbs set w3svc/WebSite/root/NTAuthenticationProviders "Negotiate,NTLM"B. .C. .D. .

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://support.microsoft.com/kb/215383/en-us

QUESTION 39Your network contains an Active Directory domain named contoso.com.You have a standard primary zone names contoso.com.You need to ensure that only users who are members of a group named Group1 can create DNS records in thecontoso.com zone. All other users must be prevented from creating, modifying, or deleting DNS records in the zone.

What should you do first?

A. Run the Zone Signing Wizard for the zone.B. From the properties of the zone, change the zone type.C. Run the new Delegation Wizard for the zone.D. From the properties of the zone, modify the Start Of Authority (SOA) record.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Hay que cambiar de primaria standard a dinamic updated con seguridad

Page 83: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 40Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1. DC1 is a DNS server for contoso.com.

The properties of the contoso.com zone are configured as shown in the exhibit. (Click the Exhibit button.)

The domain contains a server named Server1 that is part of a workgroup named Workgroup.

Server1 is configured to use DC1 as a DNS server.

You need to ensure that Server1 dynamically registers a host (A) record in the contoso.com zone.

What should you configure?

A. The Dynamic updates setting of the contoso.com zoneB. The workgroup name of Server1C. The primary DNS suffix of Server1D. The Security settings of the contoso.com zone

Correct Answer: CSection: (none)

Page 84: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:Explanation:

QUESTION 41Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. One of the domain controllers is named DC1.The DNS zone for the contoso.com zone is Active Directory-intergrated and has the default settings.A server named Server1 is a DNS server that runs a UNIX-based operating system.You plan to use Server1 as a secondary DNS server for the contoso.com zone.You need to ensure that Server1 can host a secondary copy of the contoso.com zone.

What should you do?

A. From Windows PowerShell, run the Set-DnsServerSetting cmdlet and specify DC1 as a target.B. From DNS Manager, modify the Zone Transfers settings of the contoso.com zone.C. From DNS Manager, modify the replication scope of the contoso.com zone.D. From tDNS manager, modify the Security settings of the contoso.com zone.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 42Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that runs Windows Server 2012.All client computers run Windows 8 Enterprise. DC1 contains a Group Policy object (GPO) named GPO1.You need to deploy a VPN connection to all users.

What should you configure from Users Configuration in GPO1?

A. Policies/Administrative Templates/Network/Network ConnectionsB. Policies/Administrative Templates/Network/Windows Connect NowC. Preferences/Control Panel Settings/Network OptionsD. Policies/Administrative Templates/Windows Components/Windows Mobility Centre

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 43Your network contains an Active Directory domain named contoso.com. The domain contains six domaincontrollers named DC1, DC2, DC3, DC4, DC5, and DC6. Each domain controller has the DNS Server server role installed and hosts an Active Directory-integrated zonefor contoso.com. You plan to create a new Active Directory-integrated zone named litwareinc.com that will be used for testing. You need to ensure that the new zone will be available only on DC5 and DC6.

What should you do first?

Page 85: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Create an application directory partition.B. Change the zone replication scope.C. Create an Active Directory connection object.D. Create an Active Directory site link.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc754292.aspx

QUESTION 44Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012. You enable and configure Routing and Remote Access (RRAS) on Server1. You create a user account namedUser1.You need to ensure that User1 can establish VPN connections to Server1.

What should you do?

A. Create a network policy.B. Modify the members of the Remote Management Users group.C. Create a connection request policy.D. Add a RADIUS client.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 45Server1 as a DNS server hosts a Primary zone,Server2 is the secondary zone contoso.com domain, you needto determine how long Server2 Server1 to renew regional, how to configure

A. Refresh intervalB. Restart DNSC. ForwardersD. Stub zone

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc755646(v=ws.10).aspx

Open DNS.In the console tree, right-click the applicable zone and click Properties .On the General tab, verify that the zone type is either Primary or Active Directory-integrated .Click the Start of Authority (SOA) tab.In Refresh interval , click a time period in minutes, hours, or days, and type a number in the text box.Click OK to save the adjusted interval.

Page 86: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 46You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed. On Server1, you create a network policy named PPTP_Policy.You need to configure PPTP_Policy to apply only to VPN connections that use the PPTP protocol.

What should you configure in PPTP_Policy?

A. The Service TypeB. The Tunnel TypeC. The Framed ProtocolD. The NAS Port Type

Correct Answer: BSection: (none)Explanation

Explanation/Reference:

QUESTION 47Your network contains two Active Directory forests named contoso.com and adatum.com. The contoso.com forest contains a server named server1.contoso.com. The adatum.com forest contains a server named server2.adatum.com. Both servers have the Network Policy Server role service installed. The network contains a server namedServer3. Server3 is located in the perimeter network and has the Network Policy Server role service installed. You plan to configure Server3 as an authentication provider for several VPN servers.You need to ensure that RADIUS requests received by Server3 for a specific VPN server are always forwardedto server1.contoso.com.

Which two should you configure on Server3? (Each correct answer presents part of the solution. Choose two.)

A. Network policiesB. Remote RADIUS server groupsC. Connection authorization policiesD. Remediation server groupsE. Connection request policies

Correct Answer: BESection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc754518.aspx

QUESTION 48Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012.You enable and configure Routing and Remote Access (RRAS) on Server1.You create a user account named User1. You need to ensure that User1 can establish VPN connections toServer1.

What should you do?

Page 87: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Add a RADIUS client.B. Create a connection request policy.C. Modify the members of the Remote Management Users group.D. Modify the Dial-in setting of User1.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 49Your network contains two servers named Server1 and Server2. Both servers run Windows Server 2012 andhave the DNS Server server role installed. Server1 hosts a primary zone for contoso.com. Server2 hosts a secondary zone for contoso.com. The zone is not configure to notify secondary servers of changes automatically. You update several records onServer1.You need to force the replication of the contoso.com zone records from Server1 to Server2.

What should you do from Server2?

A. Right-click Server2 and click Update Server Data Files.B. Right-click Server2 and click Refresh.C. Right-click the contoso.com zone and click Reload.D. Right-click the contoso.com zone and click Transfer from Master.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 50Your network contains an Active Directory domain named contoso.com. All client computers run Windows 8. Your company has users who work from home. Some of the home users have desktop computers. Other homeusers have laptop computers. All of the computers are joined to the domain. All of the computer accounts are members of a group namedGroup1. Currently, the home users access the corporate network by using a PPTP VPN. You implement DirectAccess by using the default configuration and you specify Group1 as the DirectAccessclient group. The home users who have desktop computers report that they cannot use DirectAccess to access thecorporate network. The home users who have laptop computers report that they can use DirectAccess to access the corporatenetwork.You need to ensure that the home users who have desktop computers can access the network by usingDirectAccess.

What should you modify?

A. The security settings of the computer accounts for the desktop computersB. The membership of the R.AS and IAS Servers groupC. The WMI filter for Direct Access Client Settings GPO

Page 88: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

D. The conditions of the Connections to Microsoft Routing and Remote Access server policy

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

QUESTION 51You have a DNS server named Server1 that has a Server Core Installation on Windows Server 2012.You need to view the time-to-live (TTL) value of a name server (NS) record that is cached by the DNS Serverservice on Server1.

What should you run?

A. Show-DNSServerCacheB. dnscacheugc.exeC. ipconfiq.exe /displaydnsD. nslookup.exe

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://www.windowsnetworking.com/articles_tutorials/Managing-DNS-servers-using-PowerShell.html

QUESTION 52Your network contains a single Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that hosts the primary DNS zone for contoso.comAll servers dynamically register their host names.You install the new Web servers that host identical copies of your company's intranet website. The servers are configured as shown in the following table.

You need to use DNS records to load balance name resolution queries for intranet.contoso.com between thetwo Web servers.

What is the minimum number of DNS records that you should create manually?

A. 1B. 2C. 3D. 4

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc772506.aspx

QUESTION 53You have a Direct Access Server named Server1 running Server 2012 .

Page 89: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

You need to add prevent users from accessing websites from an Internet connection

What should you configure?

A. Split TunnelingB. Security GroupsC. Force TunnelingD. Network Settings

Correct Answer: CSection: (none)Explanation

Explanation/Reference:C. To make Internet resources available to DirectAccess clients that use force tunneling, you can use a proxyserver, which can receive IPv6-based requests for Internet resources and translate them to requests for IPv4-based Internet resources. http://technet.microsoft.com/en-us/library/jj134204.aspx#BKMK_forcetunnelhttp://blogs.technet.com/b/tomshinder/archive/2010/03/30/more-on-directaccess-split-tunneling-and-force-tunneling.aspx

QUESTION 54Your network contains an Active Directory domain named contoso.com. The functional level of the forest isWindows Server 2008 R2. Computer accounts for the marketing department are in an organizational unit (OU) named Departments\Marketing\Computers. User accounts for the marketing department are in an OU named Departments\Marketing\Users. All of the marketing user accounts are members of a global security group named MarketingUsers. All of the marketing computer accounts are members of a global security group named MarketingComputers. In the domain, you have Group Policy objects (GPOs) as shown in the exhibit. (Click the Exhibit button.)You create two Password Settings objects named PSO1 and PSO2. PSO1 is applied to MarketingUsers. PSO2is applied to MarketingComputers. The minimum password length is defined for each policy as shown in the following table.

You need to identify the minimum password length required for each marketing user.

What should you identify?

Exhibit:

Page 90: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. 5B. 6C. 7D. 10E. 12

Correct Answer: DSection: (none)Explanation

Explanation/Reference:

QUESTION 55Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that runs Windows Server 2012. You have a Group Policy object (GPO) named GPO1 that contains several custom Administrative templates.You need to filter the GPO to display only settings that will be removed from the registry when the GPO falls outof scope. The solution must only display settings that are either enabled or disabled and that have a comment.

How should you configure the filter? To answer, select the appropriate options below. Select three.

Page 91: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. Set Managed to: YesB. Set Managed to: NoC. Set Managed to: AnyD. Set Configured to: YesE. Set Configured to: NoF. Set Configured to: AnyG. Set Commented to: YesH. Set Commented to: NoI. Set Commented to: Any

Correct Answer: AFGSection: (none)Explanation

Explanation/Reference:Las plantillas administrativas son configuraciones de directiva basadas en el Registro que aparecen en el nodo

Page 92: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Plantillas administrativas de los nodos Configuración del equipo y Configuración de usuario. Esta jerarquía secrea cuando la Consola de administración de directivas de grupo lee los archivos de plantillas administrativasbasados en XML (.admx).http://technet.microsoft.com/es-es/library/cc732634.aspx

Hay dos tipos de configuraciones de directiva de las plantillas administrativas: Administrada y Noadministrada. El servicio de directiva de grupo controla la confi guración de directiva Administrada yquita una configuración de directiva cuando ya no e sté dentro del ámbito del usuario o el equipo.

El servicio de directiva de grupo no controla la co nfiguración de directiva no administrada . Estasconfiguraciones de directiva son persistentes . El servicio de directiva de grupo no quita una configuraciónde directiva no administrada, ni siquiera si no está dentro del ámbito del usuario o el equipo. Normalmente,estos tipos de configuraciones de directiva se usan para establecer preferencias para los componentes delsistema operativo no habilitados para la directiva. También puede usar la configuración de directiva noadministrada para la configuración de aplicaciones.

El filtro de propiedades Administrada tiene tres es tados: Cualquiera, Sí y No. Si se establece este filtro depropiedades en Cualquiera , la Consola de administración de directivas de grupo mostrará todas lasconfiguraciones de directiva de plantillas administrativas. Establecer este filtro de propiedades en Sí haceque el editor sólo muestre las configuraciones de directivas de l as plantillas administrativasadministradas y oculte las no administradas . Establecer este filtro de propiedades en No hace que el editorsólo muestre las configuraciones de directivas de l as plantillas administrativas no administradas yoculte las administradas .

El filtro de propiedades Configurada tiene tres est ados: Cualquiera, Sí y No . Si se establece este filtro depropiedades en Cualquiera , la Consola de administración de directivas de grupo mostrará todas lasconfiguraciones de directiva de plantillas administ rativas ; es el valor predeterminado de este filtro.Establecer este filtro de propiedades en Sí hace que el editor sólo muestre las configuraciones de directivade plantillas administrativas configuradas y oculte las no configuradas . Establecer este filtro depropiedades en No hace que el editor sólo muestre las configuraciones de directiva de plantillasadministrativas no configuradas y oculte las config uradas.

El filtro de propiedades Comentado tiene tres estad os: Cualquiera, Sí y No . Si se establece este filtro depropiedades en Cualquiera , el Editor de administración de directivas de grupo mostrará todas lasconfiguraciones de directiva de plantillas administ rativas; es el valor predeterminado de este filtro.Establecer este filtro de propiedades en Sí hace que el editor sólo muestre la configuraciones de directivade plantillas administrativas comentadas y oculte l as que no tienen comentarios . Establecer este filtro depropiedades en No hace que el editor sólo muestre las configuraciones de directiva de pl antillasadministrativas sin comentarios y oculte las que ti enen comentarios.http://technet.microsoft.com/es-es/library/cc731054.aspx

A: Set Managed to: YesThere are two kinds of Administrative Template policy settings: Managed and Unmanaged. The Group PolicyClient service governs Managed policy settings and removes a policy setting when it is no longer within scopeof the user or computer.The Group Policy Client service does not govern unmanaged policy settings. These policy settings arepersistent. The Group Policy Client service does not remove unmanaged policy settings, even if the policysetting is not within scope of the user or computer. Typically, you use these types of policy settings to configureoptions for operating system components that are not policy enabled. You can also use unmanaged policysettings for application settings.

F: Set Configured to: AnyWe want to display both settings that are enable and disabled.

G: Set Commented to: YesOnly settings that are commented should be displayed.

Page 93: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Note: Filter with Property FiltersThe Local Group Policy Editor allows you to change the criteria for displaying Administrative Template policysettings. By default, the editor displays all policy settings, including unmanaged policy settings. However, youcan use property filters to change how the Local Group Policy Editor displays Administrative Template policysettings.There are three inclusive property filters that you can use to filter Administrative Templates. These propertyfilters include:* Managed* Configured* Commentedhttp://technet.microsoft.com/en-us/library/dd759104.aspx

QUESTION 56Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named dcl.contoso.com.You discover that the Default Domain Policy Group Policy objects (GPOs) and the Default Domain ControllersPolicy GPOs were deleted.You need to recover the Default Domain Policy and the Default Domain Controllers Policy GPOs.

What should you run?

A. dcgpofix.exe /target:domainB. gpfixup.exe /dc:dc1.contoso.co,nC. dcgpofix.exe /target:bothD. gptixup.exe /oldnb:contoso /newnb:dc1

Correct Answer: CSection: (none)Explanation

Explanation/Reference:

http://technet.microsoft.com/en-us/library/hh875588(v=ws.10).aspx

QUESTION 57Your network contains an Active Directory domain named contoso.com. Domain controllers run either WindowsServer 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1.You need to view the settings of PSO1.

Which tool should you use?

A. Group Policy ManagementB. Server ManagerC. Get-ADAccountResultantPasswordReplicationPolicyD. Active Directory Administrative Center

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc770848(v=ws.10).aspx

To view the resultant PSO for a user using Windows interfaceOpen Active Directory Users and Computers. To open Active Directory Users and Computers, click

Page 94: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Start, point to Administrative Tools , and then click Active Directory Users and Computers.On the View menu, ensure that Advanced Features is checked.In the console tree, click Users.Where?Active Directory Users and Computers\domain node\Users

In the details pane, right-click the user account for which you want to view the resultant PSO, and then clickProperties.Click the Attribute Editor tab, and then click Filter.Ensure that the Show attributes/Optional check box is selected.Ensure that the Show read-only attributes/Constructed check box is selected.Locate the value of the msDS-ResultantPSO attribute in the Attributes list.

QUESTION 58Your network contains an Active Directory domain named contoso.com. The domain contains 30 organizationalunits (OUs).You need to ensure that a user named User1 can link Group Policy Objects (GPOs) in the domain.

What should you do?

A. From the Active Directory Users and Computers, add User1 to the Network Configuration Operators group.B. From the Group Policies Management, click the contoso.com node and modify the Delegation settings.C. From the Group Policies Management, click the Group policy Objects node and modify the Delegation

settings.D. From the Active Directory Users and Computers, add User1 to the Group Policy Creator Owners group.

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc755086(v=ws.10).aspx

QUESTION 59Your network contains a single Active Directory domain named contoso.com. All domain controllers runWindows Server 2012.

The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run WindowsXP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8.All of the desktop computers are located in an organizational unit (OU) named OU1.

You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1to OU1.

You need to ensure that GPO1 is applied only to computers that run Windows XP SP3.

What should you do?

A. Modify the Security settings of OU1.B. Run the Set-GPLink cmdlet and specify the -target parameter.C. Create and link a WMI filter to GPO1.D. Run the Set-GPInheritance cmdlet and specify the -target parameter.

Correct Answer: CSection: (none)Explanation

Page 95: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:Explanation:WMI Filtering para propiedades de equipoSecurity Filtering para elegir grupos o usuariosAmbos a nivel de GPO

QUESTION 60Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012. The domain contains 500 client computers that run Windows 8 Enterprise.

You implement a Group Policy central store.

You have an application named Appl. Appl requires that a custom registry setting be deployed to all of thecomputers.

You need to deploy the custom registry setting. The solution must minimize administrator effort.

What should you configure in a Group Policy object (GPO)?

A. The Administrative TemplatesB. An application control policyC. The Group Policy preferencesD. The Software Installation settings

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:

QUESTION 61Your network contains two Active Directory forests named contoso.com and adatum.com. All domaincontrollers run Windows Server 2012.

The adatum.com domain contains a Group Policy object (GPO) named GPO1. An administrator fromadatum.com backs up GPO1 to a USB flash drive.

You have a domain controller named dcl.contoso.com. You insert the USB flash drive in dcl.contoso.com.

You need to identify the domain-specific reference in GPO1.

What should you do?

A. From Group Policy Management, run the Group Policy Results Wizard.B. From the Migration Table Editor, click Populate from GPO.C. From Group Policy Management, run the Group Policy Modeling Wizard.D. From the Migration Table Editor, click Populate from Backup.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:Explanation:The Migration Table Editor

Page 96: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

The Migration Table Editor (MTE) is provided with Group Policy Management Console (GPMC) to facilitate theediting of migration tables. Migration tables are used for copying or importing Group Policy objects (GPOs) fromone domain to another, in cases where the GPOs include domain-specific information that must be updatedduring copy or import. For information about migration tables,http://technet.microsoft.com/en-us/library/cc779961%28v=ws.10%29.aspx

QUESTION 62Your network contains an Active Directory domain named contoso.com. All client computers run Windows VistaService Pack 2 (SP2).

All client computers are in an organizational unit (OU) named 0U1. All user accounts are in an OU named OU2.All users log on to their client computer by using standard user accounts.

A Group Policy object (GPO) named GPO1 is linked to OU1. A GPO named GP02 is linked to 0U2.

You need to apply advanced audit policy settings to all of the client computers.

What should you do?

A. In GPO1, configure a startup script that runs auditpol.exe.B. In GPO2, configure a logon script that runs auditpol.exe.C. In GPO1, configure the Advanced Audit Policy Configuration settings.D. In GPO2, configure the Advanced Audit Policy Configuration settings.

Correct Answer: ASection: (none)Explanation

Explanation/Reference:Explanation: ?

QUESTION 63Your network contains an Active Directory domain named contoso.com. Domain controllers run either WindowsServer 2008, Windows Server 2008 R2, or Windows Server 2012.

You have a Password Settings object (PSOs) named PSO1.

You need to view the settings of PSO1.

Which tool should you use?

A. Group Policy ManagementB. Get-ADFineGrainedPasswordPolicyC. Get-ADDefaultDomainPasswordPolicyD. Server Manager

Correct Answer: BSection: (none)Explanation

Explanation/Reference:Explanation: The Get-ADFineGrainedPasswordPolicy cmdlet gets a fine grained password policy or performs asearch to retrieve multiple fine grained password policies.

Note:* In Windows Server 2008 (and later), you can use fine-grained password policies to specify multiple passwordpolicies and apply different password restrictions and account lockout policies to different sets of users within asingle domain. For example, to increase the security of privileged accounts, you can apply stricter settings to

Page 97: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

the privileged accounts and then apply less strict settings to the accounts of other users. Or in some cases, youmay want to apply a special password policy for accounts whose passwords are synchronized with other datasources.

Reference: Get-ADFineGrainedPasswordPolicy

QUESTION 64Your network contains an Active Directory domain named contoso.com. All domain controllers run WindowsServer 2012.

An organizational unit (OU) named OU1 contains 200 client computers that run Windows 8 Enterprise. A GroupPolicy object (GPO) named GPO1 is linked to 0U1.

You make a change to GPO1.

You need to force all of the computers in OU1 to refresh their Group Policy settings immediately.

The solution must minimize administrative effort.

Which tool should you use?

A. Group Policy Object EditorB. The Secedit commandC. Group Policy Management Console (GPMC)D. Active Directory Users and Computers

Correct Answer: CSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/es-es/library/jj134201.aspxExplanation: In the previous versions of Windows, this was accomplished by having the user run GPUpdate.exeon their computer.Starting with Windows Server® 2012 and Windows® 8, you can now remotely refresh Group Policy settings forall computers in an OU from one central location through the Group Policy Management Console (GPMC) .Or you can use the Invoke-GPUpdate cmdlet to refresh Group Policy for a set of computers, not limited to theOU structure, for example, if the computers are located in the default computers container.

Note: Group Policy Management Console (GPMC) is a scriptable Microsoft Management Console (MMC) snap-in, providing a single administrative tool for managing Group Policy across the enterprise. GPMC is thestandard tool for managing Group Policy.

Incorrect:Not B: Secedit configures and analyzes system security by comparing your current configuration to at least onetemplate.

Reference: Force a Remote Group Policy Refresh (GPUpdate)

QUESTION 65force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

A. dfsgui.mscB. ultrasoundC. rplmon D. frsutil

Correct Answer: D

Page 98: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:http://www.polymerit.co.uk/blog/2012/05/troubleshooting-sysvol-and-file-replication-service-issues/

QUESTION 66I am using a Domain Admins account to run the console and the service is running under local system.I tryapprove Requests from Pending devices, then I got notice Access Denied, (WIndows Server 2003 R2). Andwhy Architecture x64, clients are x86 ? Is that the reason and how to fix it?

A. Open WDS and right click on the server and select properties. Then click on the tab "PXE Responsesettings" and select respond to all (known and unknown) client. And also select the little checkbox below.

B. You need to grant permissions on the OU in which you want to create machine accounts for the WDSServer Machine Account.

C. To grant permissions to approve a pending computerOpen Active Directory Users and Computers . Right-click the OU where you are creating prestaged computer accounts, and then select DelegateControl . On the first screen of the wizard, click Next . Change the object type to include computers. Add the computer object of the Windows Deployment Services server, and then click Next . Select Create a Custom task to delegate .Select Only the following objects in the folder . Then select the Computer Objects check box, selectCreate selected objects in this folder , and click Next .In the Permissions box, select the Write all Properties check box, and click Finish .

D. 1. Define the OU path to add systems in WDS2. Delegate Computer object create or gretaer rights to the WDS server for the OU3. Delegate computer object create rights to your account or simply use a domain admin account to logon

Correct Answer: CSection: (none)Explanation

Explanation/Reference:He copiado todas las posibles respuestashttp://technet.microsoft.com/en-us/library/cc766320(v=WS.10).aspx#BKMK_CreatingDiscover

QUESTION 67force an authoritative and non-authoritative synchronization for DFSR-replicated SYSVOL

A. ldpB. dfsgui.mscC. ultrasoundD. rplmon

Correct Answer: ASection: (none)Explanation

Explanation/Reference:ldp: modify the distinguished name (DN) value and attribute on each of the domaincontrollers that you want to make synchronization (igualmente adsiedit)http://support.microsoft.com/kb/2218556

Page 99: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Para lanzar la replicación se usaDFSRDIAG POLLAD

dfsgui.msc: allows administrators to create DFS namespaces, add and remove targets, setthe Time to Live for targets, enable and disable referrals, enable replication for DFS root orlink targets, create custom replication schedules and topologies, and so forth. SYSVOL isintentionally protected from any editing through it s management interfaces to preventaccidents .

ultrasound: is a monitoring and troubleshooting tool for the File Replication Service (FRS).FRS is a legacy technology that replicates files and folders that are stored in Distributed FileSystem (DFS) folders or in the System Volume (SYSVOL) folder on domain controllers.

rplmon: Replication monitoring tool

QUESTION 68Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs).Currently, there are no enforced GPOs. You need to provide an Administrator named Admin1 with the ability tocreate GPOs in the domain.The solution must not provide Admin1 with the ability to link GPOs.

What should you use?

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Restore-GPOH. Set-GPInheritanceI. Set-GPLinkJ. Set-GPPermissionK. GpupdateL. Add-ADGroupMember

Correct Answer: JSection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/ee461038.aspx

QUESTION 69Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a GPO named GPO1. GPO1 contains severalGroup Policy preferences.You need to view all of the preferences configured in GPO1.

What should you use?

Page 100: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Restore-GPOH. Set-GPInheritanceI. Set-GPLinkJ. Set-GPPermissionK. GpupdateL. Add-ADGroupMember

Correct Answer: BSection: (none)Explanation

Explanation/Reference:http://cmdlet.wordpress.com/2011/08/24/episode-3-get-gporeport/

QUESTION 70Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs).Currently, there are no enforced GPOs. A network Administrator accidentally deletes the Default Domain PolicyGPO. You do not have a backup of any of the GPOs.You need to recreate the Default Domain Policy GPO.

What should you use?

A. dcgpofixB. Get-GPOReportC. Gpfixup D. Gptedit.mscE. Import-GPOF. Restore-GPOG. Set-GPInheritanceH. Set-GPLinkI. Set-GPPermissionJ. GpupdateK. Add-ADGroupMember

Correct Answer: ASection: (none)Explanation

Explanation/Reference:dcgpofixRestores the default Group Policy objects to their original state (that is, the default state after initial installation).

QUESTION 71Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain is renamed to adatum.com. Group Policies no longer

Page 101: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

function correctly.You need to ensure that the existing GPOs are applied to users and computers.You want to achieve this goal by using the minimum amount of Administrative effort.

What should you use?

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Restore-GPOH. Set-GPInheritanceI. Set-GPLinkJ. Set-GPPermissionK. GpupdateL. Add-ADGroupMember

Correct Answer: CSection: (none)Explanation

Explanation/Reference:You can use the gpfixup command-line tool to fix the dependencies that Group Policy objects (GPOs) andGroup Policy links in Active Directory Domain Services (AD DS) have on Domain Name System (DNS) andNetBIOS names after a domain rename operation.

QUESTION 72Your network contains an Active Directory domain named contoso.com. The domain contains more than 100Group Policy objects (GPOs). Currently, there are no enforced GPOs. The domain contains a top-level organizational unit (OU) for eachdepartment. A group named Group1 contains members from each department. You have a GPO named GPO1 that islinked to the domain.You need to configure GPO1 to apply settings to Group1 only.

What should you use?

A. dcgpofixB. Get-GPOReportC. GpfixupD. GpresultE. Gptedit.mscF. Import-GPOG. Restore-GPOH. Set-GPInheritanceI. Set-GPLinkJ. Set-GPPermissionK. GpupdateL. Add-ADGroupMember

Correct Answer: JSection: (none)

Page 102: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation

Explanation/Reference:

QUESTION 73Your network contains an Active Directory domain named contoso.com. A user named User1 creates a central store and opens the Group Policy Management Editor as shown in theexhibit. (Click the Exhibit button.)

You need to ensure that the default Administrative Templates appear in GPO1. What should you do?

Exhibit:

A. Link a WMI filter to GPO1.B. Add User1 to the Group Policy Creator Owners group.C. Configure Security Filtering in GPO1.D. Copy files from %Windir%\PolicyDefinitions to the central store.

Correct Answer: DSection: (none)Explanation

Explanation/Reference:http://support.microsoft.com/kb/929841

QUESTION 74Your network contains an Active Directory domain named contoso.com. Domain controllers run either WindowsServer 2008, Windows Server 2008 R2, or Windows Server 2012. You have a Password Settings object (PSOs) named PSO1. You need to view the settings of PSO1.

Which tool should you use?

A. Get-ADFineGrainedPasswordPolicyB. Get-ADAccountResultantPasswordReplicationPolicyC. Get-ADDomainControllerPasswordReplicationPolicy

Page 103: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

D. Get-ADDefaultDomainPasswordPolicy

Correct Answer: ASection: (none)Explanation

Explanation/Reference:

QUESTION 75Your network contains an Active Directory domain named contoso.com.

All user accounts reside in an organizational unit (OU) named OU1. All of the users in the marketingdepartment are members of a group named Marketing. All of the users in the human resources department aremembers of a group named HR.

You create a Group Policy object (GPO) named GPO1. You link GP01 to OU1. You configure the Group Policypreferences of GPO1 to add two shortcuts named Link1 and Link2 to the desktop of each user.

You need to ensure that Link1 only appears on the desktop of the users in Marketing and that Link2 onlyappears on the desktop of the users in HR.

What should you configure?

A. Item-level targetingB. Group Policy InheritanceC. Security FilteringD. WMI Filtering

Correct Answer: ASection: (none)Explanation

Explanation/Reference:Explanation:Explanation:A.You can use item-level targeting to change the scope of individual preference items, so they apply only toselected users or computers. Within a single Group Policy object (GPO), you can include multiple preferenceitems, each customized for selected users or comput ers and each targeted to apply settings only to therelevant users or computers .http://technet.microsoft.com/en-us/library/cc733022.aspx

B.You can further control precedence and how GPO links are applied to specific domains, sites, or organizationalunits by doing the following Changing the link order-Blocking Group Policy inheritance-Enforcing a GPO link-Disabling a GPO link

Es una configuracion a través de la consola de administracion de GPOs

C.Especifica a que grupos se aplica una GPO completa, no se puede afinar mas abajo pues es unaconfiguracion a través de la consola de administracion de GPOs

D.Filtros asociados a propiedades del equipo, a nivel de GPO, no se puede afinar mas abajo pues es una

Page 104: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

configuracion a través de la consola de administracion de GPOshttp://technet.microsoft.com/en-us/library/cc779036%28v=ws.10%29.aspx

QUESTION 76Your network contains a single Active Directory domain named contoso.com. All domain controllers runWindows Server 2012.

The domain contains 400 desktop computers that run Windows 8 and 10 desktop computers that run WindowsXP Service Pack 3 (SP3). All new desktop computers that are added to the domain run Windows 8.All of the desktop computers are located in an organizational unit (OU) named OU1.

You create a Group Policy object (GPO) named GPO1. GPO1 contains startup script settings. You link GPO1to OU1.

You need to ensure that GPO1 is applied only to computers that run Windows XP SP3.

What should you do?

A. Modify the Security settings of OU1.B. Run the Set-GPLink cmdlet and specify the -target parameter.C. Create and link a WMI filter to GPO1.D. Run the Set-GPInheritance cmdlet and specify the -target parameter.

Correct Answer: CSection: (none)Explanation

Explanation/Reference:Explanation:WMI FILTERING para poder filtrar por criterios asociados a caracteristicas del equipo

Para asegurarse de que cada GPO asociada a un grupo sólo se puede aplicar a equipos que ejecutan laversión correcta de Windows, utilice la directiva de grupo para crear y asignar filtros WMI en el GPO. Aunquese puede crear un grupo de pertenencia para cada GPO, usted entonces tiene que manejar las membresíasde los diferentes grupos. En su lugar, use sólo un grupo de miembros individuales, y dejar que los filtros WMIgarantizar automáticamente el GPO correcta a cada equipo.

Page 105: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 77Computer1 is located in an OU, and the GPO1, User1 is another OU, and as GPO2, to ensure you can applyGPO1 to User1 should be how to do?

A. Security filteringB. InheritanceC. GpupdateD. GPO

Correct Answer: ASection: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc781988%28v=ws.10%29.aspx

Page 106: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Drag&Drop

QUESTION 1Hotspot Question

You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed. Server1 is located in the perimeter network.

The IPv4 routing table on Server1 is configured as shown in the following exhibit. (Click the Exhibit button.)

Your company purchases an additional router named Router1. Router1 has an interface that connects to theperimeter network and an interface that connects to the Internet. The IP address of the interface that connectsto the perimeter network is 172.16.0.2.

You need to ensure that Server1 will route traffic to the Internet by using Router1 if the current default gatewayis unavailable.

How should you configure the static route on Server1?

To answer, select the appropriate static route in the answer area.

Exhibit:

Hot Area:

Page 107: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 108: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 2Your network contains an Active Directory domain named adatum.com. You have a Group Policy object (GPO)that configures the Windows Update settings. Currently, client computers are configured to download updates from Microsoft Update servers. Users choosewhen the updates are installed.You need to configure all client computers to install Windows updates automatically.

Page 109: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which setting should you configure in the GPO? To answer, select the appropriate setting in the answer area.

Hot Area:

Correct Answer:

Page 110: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 3Hotspot Question

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. Alldomain controllers run Windows Server 2012 and are configured as DNS servers. All DNS zones are ActiveDirectory-integrated. Active Directory Recycle Bin is enabled.

You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin.Which naming context should you use?

To answer, select the appropriate naming context in the answer area.

Hot Area:

Page 111: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 112: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd392260%28v=ws.10%29.aspxTo modify the deleted object lifetime by using Ldp.exe

To open Ldp.exe, click Start, click Run, and then type ldp.exe.

To connect and bind to the server hosting the forest root domain of your Active Directory environment, underConnections, click Connect, and then click Bind.

In the console tree, right-click the CN=Directory Service,CN=Windows NT,CN=Services,CN=Configurationcontainer, and then click Modify.

In the Modify dialog box, in Edit Entry Attribute, type msDS-DeletedObjectLifeTime.

In the Modify dialog box, in Values, type the number of days that you want to set for the tombstone lifetimevalue. (The minimum is 3 days.)

In the Modify dialog box, under Operation click Replace, click Enter, and then click Run.

QUESTION 4You have a server named Server1 that has the Web Server (IIS) server role installed.You obtain a Web Server certificate.You need to configure a website on Server1 to use Secure Socket Layer (SSL).

To which store should you import the certificate? To answer, select the appropriate store in the answer area.

Page 113: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Hot Area:

Correct Answer:

Page 114: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

QUESTION 5Your network contains a DNS server named Server1 that runs Windows Server 2012. Server1 has a zonenamed contoso.com. The network contains a server named Server2 that runs Windows Server 2008 R2.Server1 and Server2 are members of an Active Directory domain named contoso.com.You change the IP address of Server2.

Several hours later, some users report that they cannot connect to Server2.

On the affected users' client computers, you flush the DNS client resolver cache, and the users successfullyconnect to Server2.

You need to reduce the amount of time that the client computers cache DNS records from contoso.com.

Which value should you modify in the Start of Authority (SOA) record?

To answer, select the appropriate setting in the answer area.

Page 115: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Hot Area:

Correct Answer:

Page 116: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 6Your network contains an Active Directory domain named fabrikam.com. You implement DirectAccess and anIKEv2 VPN.You need to view the properties of the VPN connection.

Which connection properties should you view? To answer, select the appropriate connection properties in theanswer area.

Hot Area:

Page 117: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

QUESTION 7Your network contains a RADIUS server named Server1. You install a new server named Server2 that runs Windows Server 2012 and has Network Policy Server (NPS)installed.You need to ensure that all accounting requests for Server2 are forwarded to Server1. On Server2, you configure a Connection Request Policy.

What else should you configure on Server2? To answer, select the appropriate node in the answer area.

Hot Area:

Page 118: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

http://www.gratisexam.com/

QUESTION 8Your network contains an Active Directory domain named fabrikam.com. You implement DirectAccess.You need to view the properties of the DirectAccess connection.

Page 119: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which connection properties should you view? To answer, select the appropriate connection properties in theanswer area.

Hot Area:

Correct Answer:

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

QUESTION 9You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed.You need to configure the ports on Server1 to ensure that client computers can establish VPN connections toServer1.The solution must NOT require the use of certificates or pre- shared keys.

What should you modify? To answer, select the appropriate object in the answer area.

Hot Area:

Page 120: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: Non Mobile VCE'sExplanation

Page 121: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:Similar to B2

QUESTION 10Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShellscripts that execute when users log on to their client computer.You need to ensure that all of the scripts execute completely before the users can access their desktop.

Which setting should you configure? To answer, select the appropriate setting in the answer area.

Hot Area:

Correct Answer:

Section: Non Mobile VCE'sExplanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/cc958585.aspx

Page 122: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Run logon scripts synchronouslyDirects the system to wait for logon scripts to finish running before it starts the Windows Explorer interfaceprogram and creates the desktop.If you enable this policy, Windows Explorer does not start until the logon scripts have finished running. Thissetting assures that logon script processing is complete before the user starts working, but it can delay theappearance of the desktop .If you disable this policy or do not configure it, the logon scripts and Windows Explorer are not synchronizedand can run simultaneously.

QUESTION 11Your network contains a production Active Directory forest named contoso.com and a test Active Directoryforest named test.contoso.com. There is no network connectivity between contoso.com and test.contoso.com.The test.contoso.com domain contains a Group Policy object (GPO) named GPO1.You need to apply the settings in GPO1 to the contoso.com domain.Which four actions should you perform?To answer, move the four appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

Select and Place:

Correct Answer:

Page 123: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:The correct answer is Backup, Copy is an wrong answer because there is no trust relationship.

seehttp://technet.microsoft.com/en-us/library/cc785343%28v=ws.10%29.aspx

QUESTION 12Your network contains an Active Directory domain named contoso.com. The domain contains 30 user accountsthat are used for network administration. The user accounts are members of a domain global group namedGroup1.

You identify the security requirements for the 30 user accounts as shown in the following table.

You need to identify which settings must be implemented by using a Password Settings object (PSO) and whichsettings must be implemented by modifying the properties of the user accounts.

What should you identify?

To answer, configure the appropriate settings in the dialog box in the answer area.

Page 124: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Hot Area:

Correct Answer:

Page 125: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 13Your network contains an Active Directory domain named contoso.com.You need to audit access to removable storage devices.

Which audit category should you configure? To answer, select the appropriate category in the answer area.

Hot Area:

Page 126: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Explanation/Reference:

QUESTION 14Your network contains an Active Directory domain named contoso.com. You have several Windows PowerShellscripts that execute when client computers start. When a client computer starts, you discover that it takes a long time before users are prompted to log on.You need to reduce the amount of time it takes for the client computers to start.

Page 127: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

The solution must not prevent scripts from completing successfully.

Which setting should you configure? To answer, select the appropriate setting in the answer area.

Hot Area:

Correct Answer:

Section: (none)Explanation

Explanation/Reference:

QUESTION 15You are a network administrator of an Active Directory domain named contoso.com. You have a server namedServer1 that runs Windows Server 2012. Server1 has the Web Server (IIS) server role installed. Server1 will host a web site at URL https://secure.contoso.com. The application pool identity account of the web site will be set to a domain user account named AppPool1. You need to identify the setspn.exe command that you must run to configure the appropriate Service PrincipalName (SPN) for the web site.

Page 128: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

What should you run? To answer, drag the appropriate objects to the correct location. Each object may be usedonce, more than once, or not at all.

Select and Place:

Correct Answer:

Section: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/es-es/library/cc731241%28v=ws.10%29.aspx

Page 129: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

there is no https in the spn objects list, so https/... is no possible

En la lista de spn permitidos NO esta https, por eso no es esa

QUESTION 16Your network contains a single Active Directory domain named contoso.com. The domain contains an ActiveDirectory site named Site1 and an organizational unit (OU) named OU1. The domain contains a client computer named Client1 that is located in OU1 and Site1. You create five GroupPolicy objects (GPO). The GPOs are configured as shown in the following table.

You need to identify in which order the GPOs will be applied to Client1.

In which order should you arrange the listed GPOs? To answer, move all GPOs from the list of GPOs to theanswer area and arrange them in the correct order.

Select and Place:

Correct Answer:

Section: Non Mobile VCE'sExplanation

Page 130: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:By default settings in Group Policy Objects (GPOs) get applied in the following order: Local system policies first,then policies on the Active Directory Domain level, then policies on the Active Directory Site level and then thepolicies for all the Organization Units the computer and user are members of, starting at the root of the domain.The settings that are last applied are the settings in effect.

QUESTION 17You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed.You need to configure the ports on Server1 to ensure that client computers can establish VPN connections toServer1 by using TCP port 443.

What should you modify? To answer, select the appropriate object in the answer area.

Hot Area:

Correct Answer:

Page 131: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

QUESTION 18Your network contains an Active Directory domain named contoso.com. All servers run Windows Server 2012. The domain contains an organizational unit (OU) named FileServers_OU. FileServers_OU contains thecomputer accounts for all of the file servers in the domain.You need to audit the users who successfully access shares on the file servers.

Which audit category should you configure? To answer, select the appropriate category in the answer area.

Hot Area:

Page 132: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: Non Mobile VCE'sExplanation

Explanation/Reference:

QUESTION 19Drag and Drop Question

Your network contains an Active Directory domain named contoso.com. All client computers run Windows 7.

Group Policy objects (GPOs) are linked to the domain as shown in the exhibit. (Click the Exhibit button.)

GP02 contains user configurations only and GP03 contains computer configurations only.

You need to configure the GPOs to meet the following requirements:

Page 133: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

- Ensure that GP02 only applies to the user accounts in OU2 that are members of a global group namedGroup2.- Ensure that GP03 only applies to the computer accounts in OU3 that have more than 100 GB of free diskspace.

What should you do?

To answer, drag the appropriate setting to the correct GPO. Each setting may be used once, more than once,or not at all. You may need to drag the split bar between panes or scroll to view content.

Exhibit:

Select and Place:

Page 134: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Explanation/Reference:WMI Filtering para propiedades de equipo

Page 135: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Security Filtering para elegir grupos o usuariosAmbos a nivel de GPO

QUESTION 20Hotspot Question

Your network contains an Active Directory domain named contoso.com. The domain contains a domaincontroller named DC1 that runs Windows Server 2012.

The domain contains some test client computers that run either Windows XP, Windows Vista, Windows 7, orWindows 8. The computer accounts for the test computers are located in an organizational unit (OU) namedOU1.

You have a Group Policy object (GPO) named GP01 linked to OU1. GPO1 is used to assign severalapplications to the test computers.You need to ensure that when the test computers in OU1 restart, you can see which application installation isrunning currently.

Which setting should you modify in GPO1?

To answer, select the appropriate setting in the answer area.

Hot Area:

Correct Answer:

Page 136: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 21Your network contains an Active Directory domain named contoso.com.You have a failover cluster named Cluster1. All of the nodes in Cluster1 have BitLocker Drive Encryption(BitLocker) installed.You plan to add a new volume to the shared storage of Cluster1.

You need to add the new volume to the shared storage. The solution must meet the following requirements:Encrypt the volume.Avoid using maintenance mode on the cluster.

Which three actions should you perform?To answer, move the three appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

Select and Place:

Page 137: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 138: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: Non Mobile VCE'sExplanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/jj649829.aspx

QUESTION 22Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 has the Windows Server Update Services server role installed. You have a Group Policy object (GPO)that configures the Windows Update settings.You need to modify the GPO to configure all client computers to install Windows updates every Wednesday at01:00.

Which setting should you configure in the GPO? To answer, select the appropriate setting in the answer area.

Hot Area:

Page 139: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Page 140: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:

QUESTION 23Your network contains an Active Directory domain named corp.contoso.com. The domain contains two memberservers named Server1 and Edge1. Both servers run Windows Server 2012. Your company wants to implement a central location where the systemevents from all of the servers in the domain will be collected. From Server1, a network technician creates a collector-initiated subscription for Edge1. You discover thatServer1 does not contain any events from Edge1. You view the runtime status of the subscription as shown in the exhibit. (Click the Exhibit button.)You need to ensure that the system events from Edge1 are collected on Server1.

What should you modify? To answer, select the appropriate object in the answer area.

Exhibit:

Hot Area:

Page 141: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 142: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:On Advanced window there is buttons for changing account, event delivery optimization and protocol only. Ithink this error may be produced by wrong event selection, so we need to highlight the Select Events button.

QUESTION 24Drag and Drop Question

Your network contains an Active Directory domain named contoso.com. The domain contains two memberservers named Server1 and Server2. All servers run Windows Server 2012.

You generalize Server2.

You install the Windows Deployment Services (WDS) server role on Server1.

You need to capture an image of Server2 on Server1.

Page 143: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which three actions should you perform?

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

Select and Place:

Correct Answer:

Page 144: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:Explanation: Box 1: Start Server2 by using PXE.

Box 2: Add a capture image to Server1.

Box 3: Add an install image to Server1.

Note:* Capture images are Windows Preinstallation Environment (Windows PE) images that allow you to easilycapture the install images that you prepare using Sysprep.exe. Instead of using complex command-line tools,once you have run Sysprep.exe on your reference computer, you can boot to the Windows DeploymentServices client computer using PXE and select the capture image. When the capture image boots, it starts theCapture Image Wizard, which will guide you through the capture process and optionally upload the new installimage to a Windows Deployment Services server.

Steps/ create a capture image./ Create an install image./ Add the install image to the Windows Deployment Services server.

QUESTION 25Your network contains an Active Directory domain named contoso.com. The domain contains a member serverthat runs Windows Server 2012 and has the Windows Deployment Services (WDS) server role installed. You create a new multicast session in WDS andconnect 50 client computers to the session. When you open the Windows Deployment Services console, you discover that all of the computers are listed aspending devices. You need to ensure that any of the computers on the network can join a multicast transmission withoutrequiring administrator approval.

What should you configure? To answer, select the appropriate tab in the answer area.

Hot Area:

Page 145: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 146: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 26Your network contains an Active Directory domain called contoso.com. The domain contains a member servernamed Server1. Server1 runs Windows Server 2012.You enable the EventLog-Application event trace session.You need to set the maximum size of the log file used by the trace session to 10 MB.

From which tab should you perform the configuration? To answer, select the appropriate tab in the answerarea.

Hot Area:

Page 147: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 148: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 27Your network contains an Active Directory domain named contoso.com. The domain contains a server namedServer1 that runs Windows server 2012. Server1 has the Windows Server Update Services server role installed.You need to use the Group Policy object (GPO) to assign members to a computer group.

Which setting should you configure in the GPO? To answer, select the appropriate setting in the answer area.

Hot Area:

Page 149: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 150: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 28You have a server named Server1 that runs Windows Server 2012. Server1 has the Remote Access serverrole installed. You have a client named Client1 that is configured as an 802.1X supplicant. You need to configure Server1 tohandle authentication requests from Client1. The solution must minimize the number of authentication methods enabled on Server1.

Which authentication method should you enable? To answer, select the appropriate authentication method inthe answer area.

Hot Area:

Page 151: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Explanation/Reference:

QUESTION 29Drag and Drop Question

Page 152: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Your network contains an Active Directory domain named adatum.com. The domain contains a server namedServer1 that runs Windows Server 2012. Server1 is configured as a Network Policy Server (NPS) server and asa DHCP server.

You need to log all DHCP clients that have Windows Firewall disabled.

Which three actions should you perform in sequence?

To answer, move the three appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

Select and Place:

Correct Answer:

Page 153: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:you don´t need create a Remediation server because you only need enabling NAP in reporting mode only

Con la Network Policy se especifica que se hace cuando no se cumplen las condiciones de seguridad, eneste caso se especifica que tiene que configurar para reporting Modehttp://technet.microsoft.com/es-es/library/dd314198%28v=ws.10%29.aspx

En el Windows Security Health Validator se especifica el control de validacion, en este caso Firewallhabilitadohttp://technet.microsoft.com/es-es/magazine/2009.05.goat.aspx

Con la Health Policy se elige el Security Health Validator que se va a utilizar, se elige si habraautoremediacion y que se hace con los clientes que no pueden verificarse ni positivamente ni negativamentehttp://technet.microsoft.com/es-es/library/dd314173%28v=ws.10%29.aspx

http://ripusudan.wordpress.com/2013/03/19/how-to-configure-nap-enforcement-for-dhcp/http://technet.microsoft.com/es-es/magazine/2009.05.goat.aspxhttp://technet.microsoft.com/en-us/library/dd125379%28v=ws.10%29.aspxhttp://technet.microsoft.com/en-us/library/cc772356%28v=ws.10%29.aspx

Page 154: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that
Page 155: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that
Page 156: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that
Page 157: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 30You have a server named Server1 that has the Network Policy and Access Services server role installed. You plan to configure Network Policy Server (NPS) on Server1 to use certificate-based authentication for VPNconnections. You obtain a certificate for NPS.You need to ensure that NPS can perform certificate-based authentication.

To which store should you import the certificate? To answer, select the appropriate store in the answer area.

Hot Area:

Page 158: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 159: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

QUESTION 31Your network contains a RADIUS server named Server1. You install a new server named Server2 that runsWindows Server 2012 and has Network Policy Server (NPS) installed.You need to ensure that all accounting requests for Server2 are forwarded to Server1.On Server2, you create a new remote RADIUS server group named Group1 that contains Server1.

What should you configure next on Server2?

To answer, select the appropriate node in the answer area.

Hot Area:

Page 160: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Section: (none)Explanation

Explanation/Reference:

QUESTION 32Hotspot Question

Your network contains an Active Directory forest named contoso.com. The forest contains a single domain. All

Page 161: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

domain controllers run Windows Server 2012 and are configured as DNS servers. All DNS zones are ActiveDirectory-integrated. Active Directory Recycle Bin is enabled.

You need to modify the amount of time deleted objects are retained in the Active Directory Recycle Bin.Which naming context should you use?

To answer, select the appropriate naming context in the answer area.

Hot Area:

Correct Answer:

Page 162: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:http://technet.microsoft.com/en-us/library/dd392260%28v=ws.10%29.aspxTo modify the deleted object lifetime by using Ldp.exe

To open Ldp.exe, click Start, click Run, and then type ldp.exe.

To connect and bind to the server hosting the forest root domain of your Active Directory environment, underConnections, click Connect, and then click Bind.

In the console tree, right-click the CN=Directory Service,CN=Windows NT,CN=Services,CN=Configurationcontainer, and then click Modify.

In the Modify dialog box, in Edit Entry Attribute, type msDS-DeletedObjectLifeTime.

In the Modify dialog box, in Values, type the number of days that you want to set for the tombstone lifetimevalue. (The minimum is 3 days.)

In the Modify dialog box, under Operation click Replace, click Enter, and then click Run.

QUESTION 33Your network contains an Active Directory domain named contoso.com.

You need to create a AD Snapshot

Page 163: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Which four actions should you perform?To answer, move the four appropriate actions from the list of actions to the answer area and arrange them inthe correct order.

Select and Place:

Correct Answer:

Section: (none)Explanation

Explanation/Reference:http://www.petri.co.il/working-active-directory-snapshots-windows-server-2008.htm#Creating an Active Directory snapshot

In order to create an Active Directory snapshot you need to use the NTDSUTIL command. NTDSUTIL is builtinto Windows Server 2008. It is available if you have the Active Directory Domain Services (AD DS) server roleor the AD LDS server role installed.

Page 164: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Please follow these steps:

Log on as a member of the Domain Admins group to one of your Windows Server 2008 Domain Controllers. Open a Command Prompt window by clicking on the CMD shortcut in the Start menu, or by typing CMD andpressing Enter in the Run or Quick Search parts of the Start menu.

Note: You must run NTDSUTIL from an elevated command prompt . To open an elevated commandprompt, click Start, right-click Command Prompt, and then click Run as administrator. In the CMD window, type the following command: ntdsutil

In the CMD window, type the following command: snapshot

Note: NTDSUTIL uses nested menu commands that you type one after the other. You can type "?" at anytime to get the different command options at any menu level. Also note that you can usually type in the first fewletters of each command. For example, instead of typing "snapshots" you can simply type "sna". In the CMD window, type the following command: activate instance ntds

Before you can run the snapshot subcommand, you must run the activate instance subcommand inNTDSUTIL to set an active instance.

In the CMD window, type the following command: activate instance ntds

The result should look like this: snapshot: Activate Instance ntds Active instance set to "ntds".

In the CMD window, type the following command: create

The result should look like this:

snapshot: create Creating snapshot... Snapshot set {3a861a35-2f33-4d7a-8861-a10e47afd aba} generated successfully.

To view all available snapshots, in the CMD window, type the following command: list all

The result should look like this:

snapshot: create snapshot: List All 1: 2008/10/25:03:14 {ec53ad62-8312-426f-8ad4-d 47768351c9a} 2: C: {15c6f880-cc5c-483b-86cf-8dc2d3449348}

Next, you can leave the NTDSUTIL running, or you can quit by typing quit 2 times.

Note: NTDSUTIL allows you to run the above commands in one line. Run the following command:

ntdsutil "Activate Instance NTDS" snapshot create quit quit

You can easily automate this process. Read my "Automating the Creation of Active Directory Snapshots"article for more info.

http://technet.microsoft.com/en-us/library/cc753609(v=ws.10).aspx

Page 165: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

QUESTION 34Your network contains an Active Directory forest named contoso.com. All domain controllers run WindowsServer 2008 R2. The schema is upgraded to Windows Server 2012.Contoso.com contains two servers. The servers are configured as shown in the following table.

Server 1 and Server2 host a load-balanced application pool named AppPool1. You need to ensure that AppPool1 uses a group Manged Service Account as its identity. Which 3 actions should you perform?

Select and Place:

Correct Answer:

Section: (none)Explanation

Page 166: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Explanation/Reference:http://technet.microsoft.com/en-us/library/jj128431.aspx

"You can create a gMSA only if the forest schema has been updated to Windows Server 2012, the master rootkey for Active Directory has been deployed, and there is at least one Windows Server 2012 DC in the domain inwhich the gMSA will be created.")

QUESTION 35You have a server named Server1 that has the Web Server (IIS) server role installed. You obtain a Web Servercertificate.You need to configure a website on Server1 to use Secure Sockets Layer (SSL).

To which store should you import the certificate?

Hot Area:

Correct Answer:

Page 167: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:Similar to B14

QUESTION 36Your network contains an Active Directory domain called contoso.com. The domain contains a domaincontroller named DC1 that runs Windows server 2012.The domain contains some test client computers that run either Windows XP, Windows Vista, Windows 7, orWindows 8. The computer accounts for the test computers are located in an organizational unit (OU) named OU1.You have a Group Policy object (GPO) named GPO1 linked to OU1. GPO1 is used to assign severalapplications to the test computers.You need to ensure that when the test computers in OU1 restart, you can see which application installation isrunning currently.

Which setting should you modify in GPO1? To answer, select the appropriate setting in the answer area.

Hot Area:

Page 168: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Correct Answer:

Page 169: Braindump2go.70-411 - GRATIS EXAM...Mix-QA QUESTION 1 Your network contains a single Active Directory domain named contoso.com. The domain contains a member server named Server1 that

Section: (none)Explanation

Explanation/Reference:

http://www.gratisexam.com/